Dear SPARTA partners,
We now consider that issues #1 and #2 mentioned below have also been fixed.
Do not hesitate to contact security@sparta.eu for matters related to these issues or, more generally, to report any security-related issue.
Best regards,
--
Thibaud Antignac
CEA List
From: ANTIGNAC Thibaud <thibaud.antignac@cea.fr>
Date: Tuesday 12 March 2019 at 16:36
To: "project.consortium@internal.sparta.eu" <project.consortium@internal.sparta.eu>
Cc: <bodies.security-advisory-board@internal.sparta.eu>, "bodies.coordination@internal.sparta.eu" <bodies.coordination@internal.sparta.eu>
Subject: Concerning the security issues disclosed on 12 March 2019
Dear SPARTA partners,
Thank you to Matthias for having pointed out these three security issues:
#3, the most critical one, has been fixed almost immediately. #1 and #2 have been addressed and tests are being made to ensure they can also be considered as fixed.
The Project Security Officer of SPARTA (Florent Kirchner, CEA) scheduled a Security Advisory Board meeting to discuss about this incident and improve the procedures and technical measures. Meetings with TNK (in charge of the IT infrastructure) and UBON (having reported the issues) are also being scheduled to get more information about the circumstances. A more complete description of the incident will be sent once the whole situation is better understood.
The Security Advisory Board, composed of the Project Security Officer, the Program leaders, the Ethics Committee chair, and the Dissemination Committee chair can be contacted at bodies.security-advisory-board@internal.sparta.eu (and security@sparta.eu for external parties).
Do not hesitate to contact the Security Advisory Board or the coordination at bodies.coordination@internal.sparta.eu for matters and questions related to this incident. Please be sure we are fully committed on its complete resolution.
Best regards,
--
Thibaud Antignac
CEA List