Skip to content

Security: BansheeTech/HomeDockOS

SECURITY.md

Security Policy

How to Report Security Issues and Vulnerabilities

At HomeDock OS, your security is our top priority. If you discover any vulnerabilities or security issues, please report them directly to our security team at: πŸ“§ support@homedock.cloud

We deeply value the contributions of our community in making HomeDock OS a secure and reliable platform. Thank you for helping us improve!


Security Update History

  • ✦ Possible Self-DDoS by Enumerating Thousands of Files on Drop Zone

    • Internally Discovered – Fixed in v2.0.4.212
  • ✦ DNS Open Redirect in HTTP to HTTPS Redirector when SSL enabled

    • Internally Discovered – Fixed in v2.0.3.186
  • ✦ Open Redirect in HTTP to HTTPS Redirector when SSL enabled

    • Internally Discovered – Fixed in v2.0.3.184
  • ✦ MIME Type Validation Possible Bypass in Package Import

    • Internally Discovered – Fixed in v2.0.3.108
  • ✦ Path Traversal in Package Manager Export & Delete Operation

    • Internally Discovered – Fixed in v2.0.2.266
  • ✦ RegEx Injection in AppExplorer Search

    • Internally Discovered – Fixed in v2.0.1.102
  • ✦ Rate Limiting Bypass & IP Spoofing

    • Reported by @StringManolo – Fixed in v2.0.1.88
  • ✦ Authenticated SSRF via Host Header Manipulation

    • Reported at Secur0 by @cybernize – Fixed in v2.0.1.88
  • ✦ Path Traversal in Drop Zone File Operations

    • Reported at Secur0 by @esTse – Fixed in v2.0.1.88
  • ✦ Path Traversal & DoS via /dev/random in Drop Zone

    • Reported at Secur0 by @Ismael034 – Fixed in v2.0.1.88

There aren’t any published security advisories