In general, providing us with the address or URL of the affected system and a description of the vulnerability is sufficient. You can find a contact address and a PGP key in our security.txt at https://www.berlin.de/.well-known/security.txt
An encrypted e-mail is desirable, but not mandatory. The following also applies:
- Please be aware of the scope (only the websites named below) and of non-qualified vulnerabilities (no social engineering, DDoS, etc.)
- Do not exploit the vulnerability or problem. Do not download or upload data without authorization and do not modify or delete any data. Do not upload any code.
- Do not pass on information about the vulnerability to third parties unless you have received written approval from us.
- Provide us with sufficient information so that we can reproduce and analyze the problem (URL range, time, data for reproduction, user agent or similar).
- Please provide a contact option for further inquiries.
- Please indicate whether we may pass on your contact details to third parties for follow-up questions regarding rectification. This may be necessary when systems outside our control are involved.
- Please bear with us if we are unable to respond immediately.