Our Security Policy

Once a potential vulnerability is reported to the committers, and has been verified to be an issue, here's what to do (based on what we did for bug 5480):

Additional guidance may be required. See http://www.apache.org/security/ for more information.