DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.

DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
If you've found an issue that you believe is a security vulnerability in a released version of CloudStack, please report it to security@apache.org with details about the vulnerability, how it might be exploited, and any additional information that might be useful.
Upon notification, the ACS security team will initiate the security response procedure. If the issue is validated, the team will work on the issue and the public announcement of the vulnerability. During this time, the team will communicate with you as they proceed through the response procedure, and ask that the issue not be announced before an agreed-upon date.
The security team asks that you please do not create publicly-viewable JIRA tickets related to the issue. If validated, a JIRA ticket with the security flag set will be created for tracking the issue in a non-public manner.
The PMC has decided to create a "Security Team" for CloudStack. To read more about team membership and activities, please visit CloudStack Security Team
The scope of these procedures applies to vulnerabilities found in CloudStack releases 4.0.0-incubating and later.
CloudStack has an history that pre-dates the Apache Software Foundation. This includes the 2.0.x, 2.1.x, 2.2.x, and 3.0.x series of CloudStack releases. Vulnerabilities that are present in only these releases will be addressed by Citrix.
Some vulnerabilities may exist in ASF code releases as well as derivative works or binary distributions. This is discussed in the Distributors section below.
The following email templates could be used at certain steps on the process: https://www.apache.org/security/committers.html#possible
Dear <REPORTER>, Thank you for your report, this is to acknowledge your security report as per our security process [1]. Please allow us some time to review it and get back to you. We'll notify you once we (the Apache CloudStack PMC) accept or reject your report and discuss further about the CVE ID allocation (if accepted), as per our security process [1]. In the meanwhile, we request that no information on this report is disclosed publicly. [1] https://www.apache.org/security/committers.html#acknowledge
Dear <REPORTER>, This is to confirm that the Apache CloudStack PMC have accepted your report and we're working on a fix for the same [1]. We ask that you treat this private and confidential until this is announced publicly. The CVE ID: CVE-XXXX-YYYY has been reserved for it. [1] https://www.apache.org/security/committers.html#resolve
When a fix is available the following can also be added on the response:
Please find the attached patch for the fix for review. It may include some additional changes if we find an issue during testing. We will also share the CVE draft once ready.
Dear <REPORTER>, After investigating and reviewing your report the Apache CloudStack project PMC has decided not to accept it with reasons listed below. We do not plan to allocate a CVE for the report and we request you not to allocate one either. Reasons for not accepting the security report: <REASONS FOR REJECTION>