In the Security Policy it says:
report a Security Vulnerability via Service Desk
But the link is broken.