Full details of the CoCart Security Policy can be found on cocartapi.com/security-policy/.

Supported Versions

The CoCart Headless Security Team believes in Responsible Disclosure by alerting the security team immediately and privately of any potential vulnerabilities. If a critical vulnerability is found in any of the current versions of a CoCart plugin, we may opt to backport any patches to previous versions.

Core

VersionSupported
5.0.xYes
4.6.xYes
4.5.xYes
4.4.xYes
4.3.xYes
4.2.xNo
4.1.xNo
4.0.xNo
< 4.0.0No

Plus

VersionSupported
2.0.xYes
1.6.xYes
1.5.xYes
< 1.4.xNo

JWT Authentication

VersionSupported
2.5.xYes
2.4.xYes
2.3.xYes
2.2.xYes
2.1.xYes
2.0.xYes
< 1.0.xNo

Reporting a Vulnerability

For responsible disclosure of security issues, please submit your report based on instructions found on cocartapi.com/security-policy/. Our most critical targets are:
  • CoCart Core repository
  • CoCart Plus
  • CoCart JWT Authentication repository
  • cocartapi.com — the primary marketplace and marketing site.

Guidelines

We’re committed to working with security researchers to resolve the vulnerabilities they discover. You can help us by following these guidelines:
  • Pen-testing Production:
    • Please setup a local environment instead whenever possible. Most of our code is open source (see above).
    • If that’s not possible, limit any data access/modification to the bare minimum necessary to reproduce a PoC.
    • Don’t automate form submissions! That’s very annoying for us, because it adds extra work for the volunteers who manage those systems, and reduces the signal/noise ratio in our communication channels.
  • Be Patient - Give us a reasonable time to correct the issue before you disclose the vulnerability.