Custom Open-Source CVD Platform
Budget / Salary$5,000–10,000
TypeFreelance project
LocationRemote
Posted2 hours ago
I need a Coordinated Vulnerability Disclosure system built entirely from open-source components and delivered as software only—no appliances or proprietary add-ons. The core feature I must have is a robust workflow for tracking and managing reported vulnerabilities, from initial submission through resolution and disclosure.
The application has to run smoothly on a Linux server, so please choose libraries and frameworks that are well supported in that environment. For user access, multi-factor authentication is mandatory; I want researchers, internal engineers, and any third-party responders to sign in with something stronger than a simple password.
You are free to select or combine existing open-source projects (for example, Bug Bounty platforms, ticketing systems, or secure messaging stacks) as long as the final product offers:
• A clean web interface for submitting, updating, and viewing vulnerability tickets
• Role-based access so different stakeholders can see only what they need
• An audit trail for every action taken on a report
• Secure data storage with encryption for sensitive attachments and notes
Hand-over items: source code in a public or private repo, a one-command deployment script (Docker or Ansible preferred), and concise documentation that lets me install, configure, and maintain the system myself. I’ll test the build on a fresh Linux VM; acceptance is complete when I can reproduce the install steps and walk through a sample vulnerability report from submission to closure without errors.
The application has to run smoothly on a Linux server, so please choose libraries and frameworks that are well supported in that environment. For user access, multi-factor authentication is mandatory; I want researchers, internal engineers, and any third-party responders to sign in with something stronger than a simple password.
You are free to select or combine existing open-source projects (for example, Bug Bounty platforms, ticketing systems, or secure messaging stacks) as long as the final product offers:
• A clean web interface for submitting, updating, and viewing vulnerability tickets
• Role-based access so different stakeholders can see only what they need
• An audit trail for every action taken on a report
• Secure data storage with encryption for sensitive attachments and notes
Hand-over items: source code in a public or private repo, a one-command deployment script (Docker or Ansible preferred), and concise documentation that lets me install, configure, and maintain the system myself. I’ll test the build on a fresh Linux VM; acceptance is complete when I can reproduce the install steps and walk through a sample vulnerability report from submission to closure without errors.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.