DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
...
The ASF Security team is a CVE Project Candidate Naming Authority (CNA). CVE names are issued to vulnerabilities regardless if they are found by the project committers, members, PMCs, other ASF members, or third-parties. The ASF Security team and PMCs work from time to time with third parties who wish to perform security functions such as code audits , and bug bounties.
The ASF Security team assist the PMC PMCs in publishing a CVE once the vulnerability has been patched and a release containing the patch has been made available. Vulnerability reports are sent to common and consistent locations including security lists, project development lists, and announce@apache.org. The security team oversee oversees all reported issues across all ASF projects. The security team report reports monthly to the board and produce produces other public reports:
...