How to report potential security flaws

I'm afraid I found a potential security flaw in alfresco. What is the correct way to report, not to disclose it to the public before it gets fixed?

Regards, Michael