| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
We take the security of JunifyDB seriously. If you discover a security vulnerability, please do NOT create a public issue on GitHub.
Instead, please send an email to: security@junifydb.org (or contact the maintainers directly).
Please include:
- A description of the vulnerability and potential impact.
- Steps to reproduce or a minimal proof-of-concept repository.
- Information about affected versions and environments.
- Initial Response: Within 48 hours acknowledging receipt.
- Triage & Remediation Plan: Within 7 business days.
- Security Advisory & Patch Release: Coordinated disclosure once patch is verified.
- JunifyDB executes entirely inside the host JVM process.
- Isolation between tenants is the responsibility of the host application architecture.
- When running in shared environments, do not expose internal collections across tenant boundaries without authentication checks.
- By default, the admin console does not enforce authentication unless configured.
- In production environments, either:
- Disable the embedded HTTP server by not invoking
db.startServer(). - Set a strong API key using
server.setApiKey("your-secure-key"). - Ensure the admin port (default 8080) is bound to
127.0.0.1and protected by network firewalls.
- Disable the embedded HTTP server by not invoking
- Persistent storage engines (
FILE,B_TREE,LSM_TREE) write state to the configureddataDir. - Ensure directory permissions restrict write and read access to the OS user running the JVM process.