University of Basel · Vulnerability Disclosure

University Of Basel Vulnerability Disclosure

Vulnerability disclosure

University of Basel runs a coordinated vulnerability disclosure program on Intigriti.

UniversityHigher EducationEducationSwitzerlandBaselResearch DataResearch InformationInstitutional RepositoryOpen AccessOAI-PMHIdentity FederationLibraryResearch Computing
Program: Intigriti

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

university-of-basel-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-27'
method: searched
source: >-
  https://app.intigriti.com/programs/universityofbasel/universityofbaselvdp/detail (HTTP 200),
  confirmed against Intigriti's public programs API
  https://app.intigriti.com/api/core/public/programs (HTTP 200, 182 programs) on 2026-08-27.
provider: University of Basel
providerId: university-of-basel
program:
  published: true
  type: vulnerability-disclosure-program
  bounty: false
  platform: Intigriti
  name: University of Basel VDP
  url: https://app.intigriti.com/programs/universityofbasel/universityofbaselvdp/detail
  program_id: 618a4498-8882-406f-bfe1-b44b9acd0146
  company_handle: universityofbasel
  handle: universityofbaselvdp
  industry: education
  confidentiality: public
  status: open
  created: '2026-03-27'
  last_updated: '2026-07-09'
  last_submission: '2026-08-21'
  min_bounty:
    value: 0
    currency: EUR
  max_bounty:
    value: 0
    currency: EUR
  note: >-
    A responsible-disclosure program without bounties (min and max bounty are both EUR 0 in
    Intigriti's own public record). Scope is the university's central IT infrastructure — hosts
    under *.unibas.ch that also resolve into the university's 131.152.0.0/16 range, with
    exclusions. Safe-harbour protection is offered and researchers must not disclose without prior
    written consent. Live submissions as recently as 2026-08-21, so the program is being worked,
    not merely listed.
security_txt:
  published: false
  probes:
  - url: https://www.unibas.ch/.well-known/security.txt
    status: 503
  - url: https://ub.unibas.ch/.well-known/security.txt
    status: 404
  - url: https://edoc.unibas.ch/.well-known/security.txt
    status: 404
  - url: https://universe-intern.unibas.ch/.well-known/security.txt
    status: 200
    note: >-
      Soft 200 — the Angular SPA shell, not a security.txt. Reading the status code alone would
      have credited a document that does not exist.
  - url: https://iam.scicore.unibas.ch/.well-known/security.txt
    status: 404
  - url: https://adam.unibas.ch/.well-known/security.txt
    status: 404
  gap: >-
    THE MOST ACTIONABLE FINDING IN THIS REPO. The University of Basel runs a real, public,
    actively-worked VDP but publishes no /.well-known/security.txt on any host in the estate — so a
    researcher (or an automated scanner) who finds a flaw on edoc.unibas.ch has no machine-readable
    path to the program that already exists. One RFC 9116 file on www.unibas.ch pointing at the
    Intigriti program would close it.
notify:
  note: >-
    One finding from the 2026-08-30 pass is worth reporting through this program rather than only
    recording here: https://universe-intern.unibas.ch/api serves the complete OpenAPI 3.1
    description of the UNIverse research information system (1,671 paths, 1,170 schemas) and a
    springdoc Swagger UI to anonymous callers, on a host named "intern" belonging to the Medical
    Faculty. Data paths are bearer-gated and answer 401, so this is an exposure of the interface
    description rather than of data — but it is exactly what an institution with an open VDP would
    want told to it. The contract was deliberately NOT mirrored into this repository pending that
    conversation.
  status: not-yet-reported
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/university-of-basel-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.