Navigate to your country/region

United States

  • Afghanistan
  • Aland Islands
  • Albania
  • Algeria
  • American Samoa.
  • Andorra
  • Angola
  • Anguilla
  • Antarctica
  • Antigua and Barbuda
  • Argentina
  • Armenia
  • Aruba
  • Australia
  • Austria
  • Azerbaijan
  • Bahamas
  • Bahrain
  • Bangladesh
  • Barbados
  • Belarus
  • Belgium
  • Belize
  • Benin
  • Bermuda
  • Bhutan
  • Bolivia
  • Bosnia and Herzegovina
  • Botswana
  • Bouvet Island
  • Brazil
  • British Indian Ocean Territory
  • Brunei Darussalam
  • Bulgaria
  • Burkina Faso
  • Burundi
  • Cambodia
  • Cameroon
  • Canada
  • Cape Verde
  • Cayman Islands
  • Central African Republic
  • Chad
  • Chile
  • Mainland China
  • Christmas Island.
  • Cocos (Keeling) Islands
  • Colombia
  • Comoros
  • Congo
  • Congo, Democratic Republic
  • Cook Islands
  • Costa Rica
  • Ivory Coast
  • Croatia
  • Cuba
  • Cyprus
  • Czech Republic
  • Denmark
  • Djibouti
  • Dominica
  • Dominican Republic
  • Ecuador
  • Egypt
  • El Salvador
  • Equatorial Guinea
  • Eritrea
  • Estonia
  • Ethiopia
  • Falkland Islands (Malvinas)
  • Faroe Islands
  • Fiji
  • Finland
  • France
  • French Guiana
  • French Polynesia
  • French Southern Territories
  • Gabon
  • Scotland
  • Gambia
  • Georgia
  • Germany
  • Ghana
  • Gibraltar
  • Greece
  • Greenland
  • Grenada
  • Guadeloupe
  • Guam
  • Guatemala
  • Guernsey
  • Guinea
  • Guinea-Bissau
  • Guyana
  • Haiti
  • Heard Island & McDonald Islands.
  • Holy See (Vatican City)
  • Honduras
  • Hong Kong, SAR
  • Hungary
  • Iceland
  • India
  • Indonesia
  • Iran, Islamic Republic of
  • Iraq
  • Ireland
  • Isle of Man
  • Israel
  • Italy
  • Jamaica
  • Japan
  • Jersey
  • Jordan
  • Kazakhstan
  • Kenya
  • Kiribati
  • Korea
  • Kuwait
  • Kyrgyzstan
  • Lao People's Democratic Republic
  • Latvia
  • Lebanon
  • Lesotho
  • Liberia
  • Libyan Arab Jamahiriya
  • Liechtenstein
  • Lithuania
  • Luxembourg
  • Macao, SAR
  • Macedonia
  • Madagascar
  • Malawi
  • Malaysia
  • Maldives
  • Mali
  • Malta
  • Marshall Islands
  • Martinique
  • Mauritania
  • Mauritius
  • Mayotte
  • Mexico
  • Micronesia, Federated States of
  • Moldova
  • Monaco
  • Mongolia
  • Montenegro
  • Montserrat
  • Morocco
  • Mozambique
  • Myanmar
  • Namibia
  • Nauru
  • Nepal
  • Netherlands
  • Netherlands Antilles
  • New Caledonia
  • New Zealand
  • Nicaragua
  • Niger
  • Nigeria
  • Niue
  • Norfolk Island
  • Northern Mariana Islands.
  • Norway
  • Oman
  • Pakistan
  • Palau
  • Panama
  • Papua New Guinea
  • Paraguay
  • Peru
  • Philippines
  • Pitcairn
  • Poland
  • Portugal
  • Puerto Rico.
  • Qatar
  • Reunion
  • Romania
  • Russian Federation
  • Rwanda
  • Saint Barthelemy
  • Saint Helena
  • Saint Kitts and Nevis
  • Saint Lucia
  • San Martín
  • St. Pierre and Miquelon.
  • Saint Vincent and the Grenadines
  • Samoa
  • San Marino
  • Sao Tome and Principe
  • Saudi Arabia
  • Senegal
  • Serbia
  • Seychelles
  • Sierra Leone
  • Singapore
  • Slovakia
  • Slovenia
  • Solomon Islands
  • Somalia
  • South Africa
  • South Georgia and Sandwich Islands.
  • Spain
  • Sri Lanka
  • Sudan
  • South Sudan
  • Suriname
  • Svalbard and Jan Mayen
  • Swaziland
  • Sweden
  • Switzerland
  • Syrian Arab Republic
  • Taiwan, China
  • Tajikistan
  • Tanzania
  • Thailand
  • Timor-Leste
  • Togo
  • Tokelau
  • Tonga.
  • Trinidad and Tobago
  • Tunisia
  • Turkey
  • Turkmenistan
  • Turks and Caicos Islands
  • Tuvalu
  • Uganda
  • Ukraine
  • United Arab Emirates
  • United Kingdom
  • United States
  • United States Outlying Islands.
  • Uruguay
  • Uzbekistan
  • Vanuatu
  • Venezuela
  • Viet Nam
  • British Virgin Islands.
  • Virgin Islands, USA.
  • Wallis and Futuna
  • Yemen
  • Zambia
  • Zimbabwe

Web Clubs

LALIGA

Institutional

LALIGA

with sport

LALIGA

Group

LALIGA

INSTITUTIONAL

LALIGA WITH

SPORT

LALIGA

GROUP

1. Introduction and Object

LaLiga Group International, S.L. (hereinafter "LaLiga") is committed to information security of its products and services and, thus, it is top priority.

Likewise, LaLiga respects and appreciates cybersecurity researchers and ethical hackers who cooperate to notify security vulnerabilities responsibly so as to fix them diligently.

For these reasons, LaLiga supports people who discover and report security vulnerabilities through the current Vulnerability Disclosure Policy (hereinafter, the "Policy").

This document defines the scope, terms and conditions, and the procedure to report vulnerabilities for outsiders.


2. Scope

The Policy scope includes LaLiga web and mobile apps which link with it.

However, any software component, library, or software development kit (SDK) external to LaLiga is considered deliberately out of scope, despite the fact it is built in.


3. Terms and Conditions

According to the European Union Agency for Cybersecurity (ENISA), the Policy defines a vulnerability as a weakness or a design or implementation error that can lead to an event that compromises the security of a device, operating system, network, programme or a protocol involved in any of the above.

Considering the above, LaLiga commit to:

  • Investigate vulnerability reports diligently.
  • Make reasonable efforts to fix verified security failures.
  • Not recommend or pursue legal action related to vulnerability reports complying with the Policy.

Similarly, cybersecurity researchers or ethical hackers must comply with:

  • Act in good faith.
  • Comply with all applicable laws.
  • Notify LaLiga of security vulnerabilities as soon as possible.
  • Not gain personal advantage nor advantage for third parties of security vulnerabilities.
  • Not disclosure publicly nor share any security vulnerability with third parties without written explicit consent from LaLiga.
  • Not perform actions nor manifestations which would have a negative impact on LaLiga or its reputation.
  • Not access, compromise, modify nor harm data, systems, or services which is not your own.
  • Not disrupt nor degrade LaLiga apps, systems, or services.
  • Not use automated vulnerability scanners.
  • Not use social engineering, spam, phishing, brute force, malware, denial of service nor physical attacks.

 

4. Notification procedure

In case a cybersecurity researcher or ethical hacker discover a security vulnerability within the Policy scope, it could be notified LaLiga (in English or Spanish) at the email address cvd[@]laliga[.]es, providing the following information:

  • Affected app and version.
  • Type, high level summary and potential impact.
  • Technical details and evidence.
  • Reproducible steps and/or a working proof of concept (PoC).

In addition, security vulnerabilities could be reported to the reference security incident response center for citizens and private law entities in Spain (INCIBE-CERT), according to its vulnerability disclosure policy.