Skip to content

Commit d23f0e8

Browse files
authored
Update IRP.md
Signed-off-by: |7eter l-|. l3oling <[email protected]>
1 parent 15876e1 commit d23f0e8

File tree

1 file changed

+1
-2
lines changed

1 file changed

+1
-2
lines changed

IRP.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -53,8 +53,7 @@ Applies to security incidents that affect the `oauth2` codebase, releases (gems)
5353
- Add/adjust tests and CI checks to prevent regressions.
5454
- If credentials or infrastructure were compromised, rotate secrets and audit access.
5555

56-
Severity classification (guidance)
57-
---------------------------------
56+
## Severity classification (guidance)
5857
- High/Critical: Remote code execution, data exfiltration, or any vulnerability that can be exploited without user interaction. Immediate action and prioritized patching.
5958
- Medium: Privilege escalation, sensitive information leaks that require specific conditions. Patch in the next release cycle with advisory.
6059
- Low: Minor information leaks, UI issues, or non-exploitable bugs. Fix normally and include in the next scheduled release.

0 commit comments

Comments
 (0)