University of Basel · Vulnerability Disclosure
University Of Basel Vulnerability Disclosure
Vulnerability disclosure
University of Basel runs a coordinated vulnerability disclosure program on Intigriti.
UniversityHigher EducationEducationSwitzerlandBaselResearch DataResearch InformationInstitutional RepositoryOpen AccessOAI-PMHIdentity FederationLibraryResearch Computing
Program: Intigriti
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-27'
method: searched
source: >-
https://app.intigriti.com/programs/universityofbasel/universityofbaselvdp/detail (HTTP 200),
confirmed against Intigriti's public programs API
https://app.intigriti.com/api/core/public/programs (HTTP 200, 182 programs) on 2026-08-27.
provider: University of Basel
providerId: university-of-basel
program:
published: true
type: vulnerability-disclosure-program
bounty: false
platform: Intigriti
name: University of Basel VDP
url: https://app.intigriti.com/programs/universityofbasel/universityofbaselvdp/detail
program_id: 618a4498-8882-406f-bfe1-b44b9acd0146
company_handle: universityofbasel
handle: universityofbaselvdp
industry: education
confidentiality: public
status: open
created: '2026-03-27'
last_updated: '2026-07-09'
last_submission: '2026-08-21'
min_bounty:
value: 0
currency: EUR
max_bounty:
value: 0
currency: EUR
note: >-
A responsible-disclosure program without bounties (min and max bounty are both EUR 0 in
Intigriti's own public record). Scope is the university's central IT infrastructure — hosts
under *.unibas.ch that also resolve into the university's 131.152.0.0/16 range, with
exclusions. Safe-harbour protection is offered and researchers must not disclose without prior
written consent. Live submissions as recently as 2026-08-21, so the program is being worked,
not merely listed.
security_txt:
published: false
probes:
- url: https://www.unibas.ch/.well-known/security.txt
status: 503
- url: https://ub.unibas.ch/.well-known/security.txt
status: 404
- url: https://edoc.unibas.ch/.well-known/security.txt
status: 404
- url: https://universe-intern.unibas.ch/.well-known/security.txt
status: 200
note: >-
Soft 200 — the Angular SPA shell, not a security.txt. Reading the status code alone would
have credited a document that does not exist.
- url: https://iam.scicore.unibas.ch/.well-known/security.txt
status: 404
- url: https://adam.unibas.ch/.well-known/security.txt
status: 404
gap: >-
THE MOST ACTIONABLE FINDING IN THIS REPO. The University of Basel runs a real, public,
actively-worked VDP but publishes no /.well-known/security.txt on any host in the estate — so a
researcher (or an automated scanner) who finds a flaw on edoc.unibas.ch has no machine-readable
path to the program that already exists. One RFC 9116 file on www.unibas.ch pointing at the
Intigriti program would close it.
notify:
note: >-
One finding from the 2026-08-30 pass is worth reporting through this program rather than only
recording here: https://universe-intern.unibas.ch/api serves the complete OpenAPI 3.1
description of the UNIverse research information system (1,671 paths, 1,170 schemas) and a
springdoc Swagger UI to anonymous callers, on a host named "intern" belonging to the Medical
Faculty. Data paths are bearer-gated and answer 401, so this is an exposure of the interface
description rather than of data — but it is exactly what an institution with an open VDP would
want told to it. The contract was deliberately NOT mirrored into this repository pending that
conversation.
status: not-yet-reported
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/university-of-basel-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.