This policy applies to all repositories in the NrgXnat
organization, including XNAT core, XNAT plugins, and related tools, unless a
repository provides its own SECURITY.md.
| Version | Supported |
|---|---|
| 1.10.x | ✅ |
| 1.9.3.x | |
| < 1.9.3 | ❌ |
Fixes for 1.9.3.x are provided at the XNAT team's discretion, typically for critical or high-severity issues. For the latest features and fixes, we recommend upgrading to the latest release.
For each plugin, only the latest release is supported. Security fixes are delivered in a new plugin release rather than backported to older plugin versions. To receive a fix, upgrade to the latest release of the plugin that is compatible with a supported XNAT version.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Report the issue privately in the repository where the vulnerability exists:
- Go to the affected repository (for example,
NrgXnat/xnatfor XNAT core, or the repository for the affected plugin). - Open the Security tab.
- Click Report a vulnerability.
If you're not sure which repository is affected, report it in NrgXnat/xnat.
Prefer email? Write to [email protected] instead. Use email if you need to attach logs, screenshots, or other files, or if the affected repository is archived or doesn't offer the Report a vulnerability button.
Please include a detailed description of the issue, steps to reproduce it, its potential impact, and your environment:
- Affected repository or plugin
- XNAT version
- Plugin versions
- Tomcat version
- Postgres version
- OS version
- Browser version
Do not include protected health information (PHI) or real subject data in your report, logs, or screenshots. Please redact or de-identify them first.
Thanks for helping us keep XNAT secure!