Reporting a vulnerability
How to report a security problem in COMA privately, and what to include.
If you find a security problem in COMA, report it privately. Do not open a public issue, post in a discussion or share details in public until a fix is released.
Where to report
- While COMA is in pre-alpha, its repository is private. Report through the contact listed on coma.sh.
- Once the repository is public, use GitHub's private vulnerability reporting on the COMA repository.
What to include
A report we can reproduce gets fixed faster. Include what you can of:
- the COMA version and build: the output of
coma version; - your computer's OS and architecture, and the machine's Linux distribution;
- the engine and its version (
coma engine inspect --machine <name>shows it); - what an attacker can do, and what they need first: for example network access to the machine, an account on your computer, or a malicious
coma.yamlor Compose file; - the steps to reproduce, with the smallest setup that shows the problem;
- what you expected and what happened;
- whether the problem is already public, and whether you plan to publish.
coma doctor --json output helps with local problems. Check it before you send it: replace host names, user names, IP addresses and paths you do not want to share.
Do not include real credentials, private keys or other people's data. If a proof of concept needs a secret, describe it instead.
Scope
In scope: the coma CLI, comad, the endpoint and its request rewriting, sync and the coma-sync helper, port mirroring, coma machine bootstrap, and these docs where they describe security behaviour.
Examples of what to report:
- a request through COMA's endpoint that publishes a port on a machine's public interfaces;
- a bind mount that escapes the synced directory;
- a host key accepted without verification;
- a secret written to COMA's logs, state or config;
- another local user reaching your endpoint socket;
- sync deleting or overwriting a file changed on the machine in the default mode.
Problems in Docker, Podman or Mutagen themselves belong with those projects. If COMA makes one of them worse, report it here too.
See the Security model for what COMA protects and what it does not.