WSO2 Security and Compliance Documentation
Security and compliance resources for WSO2 products and cloud services, covering secure engineering practices, deployment hardening guidance, vulnerability management processes, and public security advisories.
Found a security issue? Report it privately through the appropriate WSO2 security reporting channel. See the vulnerability reporting guidelines for what to include.
Security Processes
Organizational security workflows, governance, incident handling, and vulnerability management practices.
Processes & Programs
Secure software development lifecycle, vulnerability management workflow, cloud security controls aligned with the CSA DevSecOps pillars, and the SaaS incident notification process.
Security Guidelines
Technical implementation guidance for secure engineering and hardened deployments.
Engineering & Operations
Secure coding standards, OWASP Top 10 prevention, security analysis tooling for WSO2 product teams, and hardening guidance for production deployments.
Security Announcements
Product advisories, CVE analysis, cloud security bulletins, and clarifications on industry incidents relevant to WSO2 products and customers.
Security Advisories
Public advisories for confirmed vulnerabilities in WSO2 products, including affected versions, CVSS severity, assigned CVE IDs, and the recommended fix or mitigation.
Third-Party CVE Analysis
Assessment of third-party CVEs flagged against WSO2 products, covering whether each CVE is exploitable in the WSO2 context, the reasoning, and any required customer action or mitigation.
Cloud Security Bulletins
Periodic bulletins for WSO2 cloud services (Asgardeo, Choreo, and the WSO2 API Platform) that summarize security events and changes within each reporting period.
Incident Clarifications
Analysis and clarifications for public security incidents and supply-chain events relevant to WSO2 products and services, covering the impact assessment and any required customer action.
Reporting
Channels for reporting vulnerabilities, abuse, and malicious content, alongside the researcher reward and acknowledgement program.
Report an Issue
Private mailing lists (with GPG keys) for reporting vulnerabilities in WSO2 products and infrastructure, and guidance on what to include in a report.
Reward & Acknowledgement
Eligibility criteria for the reward program and the Security Hall of Fame listing researchers acknowledged for past disclosures.