Security Severity Ratings/Merge: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
Line 81: Line 81:
Inconsistency in reproducing the issue
Inconsistency in reproducing the issue
|-
|-
| <b>sg-nse</b>
| <b>sg-other</b>
|Bugs that may not be exploitable security issues but are kept confidential to protect sensitive information.
|Bugs that may not be exploitable security issues but are kept confidential to protect sensitive information.
|Bugs that contain sensitive information about the bug submitter or another user
|Bugs that contain sensitive information about the bug submitter or another user
Line 248: Line 248:
;'''Normal''': Internal vulnerability with a low likelihood of being remotely exploitable.
;'''Normal''': Internal vulnerability with a low likelihood of being remotely exploitable.
|}
|}
==Transition Plan==
==Transition Plan==
{| style="width: 800px;" class="wikitable collapsible collapsed fullwidth-table"
{| style="width: 800px;" class="wikitable collapsible collapsed fullwidth-table"

Revision as of 18:03, 21 March 2012

Security bugs are rated by specifying "sec-<rating>" in the "Keyword" field in bugzilla. For example, a bug with a Critical security rating would be marked as "sec-critical".

Severity Ratings

Additional Security Status Codes

If a potential security issue has not yet been assigned a severity rating, or a rating is not appropriate, the whiteboard may instead contain one of the following security status codes.

Transition Plan

Example Searches

Archive

archive