question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

Report Template proposition

See original GitHub issue

Hi Guys,

There is a report template put in when you choose to submit new vulnerability report to Node.js Ecosystem Bug Bounty Program.

I think it can be tuned up a little bit 😉

Here’s my proposition (this is exactly the same template I am using to report to your program).

Why tho?

I found that current template contains some unnecessary sections. For example, an Impact which is now a separate field in Report form itself, so there is no need to put twice the same information.

Also, Summary and Description looks to me like something what can be merged into one, where vulnerability can be described.

Report Template proposition

So, making long story short - here’s proposed template:

There is [VULNERABILITY] in [MODULE]
It allows [WHAT IT ALLOWS - EG. READ ARBITRARY FILES, READ DATA FROM DATABASE ETC.]

## Module

**[MODULE NAME]**

[DESCRIPTION - JUST FOR REFERENCE; COPIED FROM NPM MODULE PAGE]

https://www.npmjs.com/package/[MODULE NAME]

version: [MODULE VERSION]

Stats
1 downloads in the last day
10 downloads in the last week
100 downloads in the last month

~1200 estimated downloads per year [JUST FOR REFERENCE,  ~DOWNLOADS PER MONTH*12]

## Description

[DESCRIPTION ABOUT HOW VULNERABILITY WAS FOUND AND HOW IT CAN BE EXPLOITED, HOW IT HARMS PACKAGE USERS (DATA MODIFICATION/LOST, SYSTEM ACCESS, OTHER]

## Steps To Reproduce:

[DETAILED STEPS TO REPRODUCE WITH ALL REQUIRED REFERENCES/STEPS/COMMANDS. IF THERE IS ANY EXPLOIT CODE ORE REFERENCE TO THE PACKAGE SOURCE CODE - THIS IS THE PLACE WHERE IT SHOULD BE PUT]

## Supporting Material/References:

[ALL TECHNICAL INFORMATION ABOUT STACK WHERE VULNERABILITY WAS FOUND GOES HERE]:

- [OPERATING SYSTEM VERSION - MANDATORY]
- [NODEJS VERSION - MANDATORY]
- [NPM VERSION - MANDATORY]
- [BROWSERS VERSIONS, IF APPLICABLE] 
- [OTHER SOFTWARE USED TO EXPLOIT VULNERABILITY AND THEIR VERSIONS, IF APPLICABLE]

## Wrap up

[HUNTER'S COMMENTS AND FUNNY MEMES GOES HERE]


Anyhting missed?

Is there anything from your point of view which I’ve missed here and you think it should be added? Please feel free to put any ideas in the comments 😃

Regards,

Rafal ‘bl4de’ Janicki

Issue Analytics

  • State:closed
  • Created 6 years ago
  • Reactions:1
  • Comments:18 (15 by maintainers)

github_iconTop GitHub Comments

1reaction
lirantalcommented, Feb 23, 2018

Make sense. I also updated the markdown headers a bit to make more sense so that there’s one head section for the module information and the 2nd for the vulnerability information.

I updated my comment here: https://github.com/nodejs/security-wg/issues/114#issuecomment-364238635 with the proposed changed (but I also updated it on the H1 report form already 😉 )

1reaction
vdeturckheimcommented, Feb 18, 2018

Aweosme, thanks @lirantal !

Read more comments on GitHub >

github_iconTop Results From Across the Web

32 Sample Proposal Templates in Microsoft Word - Hloom
1. This should grab the attention of the reader. Take this part to establish your agreement about the issue and begin to set...
Read more >
How to Write a Business Proposal (+ Examples & Templates)
In this in-depth guide to creating business proposals, we show you how to close more deals, make more sales and crush your business...
Read more >
Business Proposal Report | Free proposal template - Piktochart
Create eye-catching proposals in minutes! Use this business proposal report template to get started. No design skills needed.
Read more >
How to Write a Business Proposal [Examples + Template]
This template will include a project summary, project activities (including deliverables), a timeline, and more.
Read more >
How to Write an Inspiring Value Proposition (Free Template ...
A value proposition (VP) explains how customers can benefit from purchasing your product. In this declarative statement, you'll convince ...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found