@@ -39,12 +39,17 @@ team](https://www.apache.org/security/) via email to
3939vulnerability, how it might be exploited, and any additional information that
4040might be useful.
4141
42- Upon notification, the ASF security team will work with the CloudStack PMC
43- through validation and fixing the issue. If the issue is validated, it generally
44- takes 2-4 weeks from notification to public announcement of the vulnerability.
45- During this time, the team will communicate with you as they proceed through the
46- response procedure, and ask that the issue not be announced before an
47- agreed-upon date.
42+ Upon notification, the ASF security team will work with the CloudStack
43+ PMC through validation and fixing the issue. If the issue is
44+ validated, it will still take time to fix the issue. The amount of
45+ time depends on the availability of volunteers and number people
46+ involved that have a stake in the issue. In the past this would
47+ generally take 2-4 weeks from notification to public announcement of
48+ the vulnerability. In later years it has turned out to take more time
49+ (up to six months in some cases) due to parallel work on multiple
50+ issues. During this time, the team will communicate with you as they
51+ proceed through the response procedure, and ask that the issue not be
52+ announced before an agreed-upon date.
4853
4954** Please do not create publicly-viewable JIRA tickets related to the issue** . If
5055validated, a JIRA ticket with the security flag set will be created for tracking
0 commit comments