Only the latest released version of
invoice4jis supported and receive security fixes.
If you discover a security vulnerability in invoice4j, please do not open a public GitHub issue.
Instead, report it privately by email:
Email: [email protected]
Please include as much information as possible:
- Description of the vulnerability
- Steps to reproduce
- Affected version(s)
- Proof of concept (if available)
- Suggested mitigation (optional)
After receiving a report, we will:
- Acknowledge receipt
- Investigate the reported issue
- Develop and test a fix if necessary
- Publish a patched release.
- Credit the reporter (if desired)
Security reports may include issues such as:
- XML parsing vulnerabilities
- XXE (XML External Entity) attacks
- XML signature verification issues
- Denial of Service (DoS)
- Dependency vulnerabilities
- Data integrity issues
- Injection vulnerabilities
Please allow reasonable time for the issue to be investigated and fixed before publicly disclosing any vulnerability.
We appreciate responsible disclosure and will work with reporters to resolve issues as quickly as possible.