{"id":"326ffefd-402d-4c50-a6c5-490f1286413a","engagementId":"89ce5856-4e0d-4d5f-8151-55575aeddbd5","data":{"brief":{"id":"e1a661bf-614a-4221-9aca-163041c05393","name":"Aiven Managed Bug Bounty","tagline":"Aiven is a trusted open source data platform for everyone. Please submit your findings to this Bug Bounty program.","description":"\u003cp\u003eAiven is a next-generation managed cloud database platform as a service. Its focus is in ease of adoption, high fault resilience, customer's peace of mind and advanced features at competitive price points. See \u003ca href=\"https://aiven.io/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://aiven.io/\u003c/a\u003e for more information.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect, and Aiven believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eWe will not accept issues that have been previously reported to Aiven through other channels, regardless if whether they have not yet been reported within the Bugcrowd platform.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Aiven not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Aiven, you can report it.  However, be aware that it is ineligible for rewards or points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eMaking the Most of our Program\u003c/h2\u003e\n\n\u003ch3\u003eWe strongly recommend focusing on our managed database applications\u003c/h3\u003e\n\n\u003cp\u003eVulnerabilities in our website are frequently reported and have a high number of duplicates, whereas most issues reported with our managed database applications are unique.  For a demonstration of how to create managed databases in Aiven, \u003ca href=\"https://www.youtube.com/watch?v=t95IQ0kpbFY\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eplease see this quick video\u003c/a\u003e.  If you want to automate things, \u003ca href=\"https://aiven.io/devops\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ewe provide a spectrum of DevOps tools and interfaces to make this easy\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eThe security of our customers' data from cross-account access and the security of our hosts and our orchestration plane are among Aiven's top priorities; reports of demonstrated security problems impacting these priorities are particularly valuable to Aiven.\u003c/p\u003e\n\n\u003cp\u003eYou are welcome to use our free tier services and trial credits to use the managed database services.  If your account needs additional trial credits beyond the base initial amount, we are happy to grant some free of charge to support legitimate testing activity; please reach out through the program.\u003c/p\u003e\n\n\u003cp\u003eIf your vulnerability report is based on the version of running software, please attempt a proof of concept on an Aiven system first.  We have mitigated many issues that arise from hosting our services in a public cloud environment, and the software we are running may differ from upstream, so for example a CVE against a particular version of Postgres may not be exploitable on Aiven even if we are running the version to which it applies.\u003c/p\u003e\n\n\u003ch3\u003eAiven's Permission Model\u003c/h3\u003e\n\n\u003cp\u003eAiven expects that, regardless of what might be shown in the web console:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePermissions that are granted in the API are intentionally granted, whether or not they are \"greyed out\" or accessible in the console; however, access that is granted to resources with which the attacker has no relationship at all is likely a bug.\u003c/li\u003e\n\u003cli\u003eUsers who are allowed to access the service user (usually avnadmin) are intentionally granted access to all of the service functionality, regardless of whether the Aiven API allows particular operations that influence the service configuration.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eProgram Rules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eOnly use your @bugcrowdninja email addresses for registering testing accounts. Do not use any other email addresses such as @gmail.com for security testing.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eOnly interact with accounts and services you own or with explicit permission of the account holder. Specifically, take note of rules on aivencloud.com domain.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eOnly use Aiven services via the Aiven brand.  \u003cstrong\u003eUsing our services through our business partners' interfaces is out of scope\u003c/strong\u003e.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMake a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSocial engineering (e.g. phishing, vishing, smishing) is prohibited.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou are testing on production. Behavior that compromises the stability and integrity of the site is out of scope. For example, do not target other users' data (instead, please use one of your other sets of credentials), delete/remove/edit parts of the site, engage any sort of DoS or DDoS attack, and/or compromise any target's ability to function for other users. If you believe that you have found a vulnerability of this nature, please stop further testing and report it.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eExploit Chain Testing\u003c/h2\u003e\n\n\u003cp\u003eThe focus of the program is initial access vectors.  We are interested in your exploration of the following chained goals, to demonstrate severity:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eCredential theft\u003c/strong\u003e.  If you find a credential, please report it (you may include the credential in your report).  We will determine the scope of access of the credential; please do not attempt to discover the scope of access yourself, as you will create needless alerts and we will shut all your services off.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eAccess to internal network services\u003c/strong\u003e.  Look specifically for internal services to which you can gain substantial access.  Mere network scanning or open ports are not sufficient to demonstrate impact; at minimum, positively identify the type of service to which you can pivot.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eCross-account access\u003c/strong\u003e.  We are interested in avenues to make authenticated access to other accounts' services where the other account has not allowed this access - please use only other accounts that you own, not random customers.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAs these types of exploitation frequently trigger alarms, we request that you report what you have found as soon as possible.  We will rate such vulnerabilities according to the access that the initial access vector provides.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eReport Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eWe are interested in real-world vulnerabilities that have material security impact. Theoretical vulnerabilities without a proof of concept are not eligible for reward. The proof of concept has to be specific to (and work on) the Aiven domain or resource your report is about.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003ePlease provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, there will be unnecessary delays in processing the issue. Report quality is taken into account when making decisions about reward and disclosure.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSubmit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo not submit any attachments unless requested by our team. Screenshots are accepted, but videos, binaries and so on are not okay.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eApplications within the scope of this engagement share the same codebase. Vulnerability reports submitted on the same vulnerability across different endpoints belonging to Aiven are not eligible for multiple rewards. Multiple reports on the same vulnerability will be considered duplicates. Please submit a single report. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eReports of software versions with known vulnerabilities (e.g. CVE) found on our domains must have a working proof of concept, or they will be marked spam. Vulnerabilities that are not exploitable as deployed on an in-scope domain or service are out of scope.  Please also note that Aiven monitors dependency versions and it is highly likely we are already internally tracking these issues, and so they are likely to be marked as duplicates if they do not disclose any threat beyond direct exploitation of the known vulnerability.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo not submit scanner output. In general, automated tools and scanners won't provide you much help, because we run them ourselves already. If your report consists only of pasted scanner output, we will mark it spam.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eWhile we do not prohibit the use of AI tooling to help write vulnerability reports, we greatly value conciseness and rigour.  We also request that you check your findings and reproduction yourself to avoid false positives.  Reports that are excessively long due to generated text are likely to experience delayed triage, and repeated submission of generated false positives may result in a ban.  You may not automate submission of vulnerabilities to this program; there must be a human in the loop.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eWe will pay a P4 bounty for issues that are limited to misleading documentation and do not require code changes to fix, or issues resulting in customer confusion about a security feature that only require changes to explanatory strings and elements in user interface layers, as long as the confusion results in a likely security impact.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eDuplicative Reports\u003c/h3\u003e\n\n\u003cp\u003eWe want every valid vulnerability discovered by the public to get exactly one bounty.  Therefore, we do not support bounty strategies that involve reporting the same issue to dozens of programs rapid-fire in an attempt to get paid for the same issue by many programs.  Issues that are more appropriately the responsibility of another entity may be forwarded to them and may not receive a bounty.  For example, if you find an issue that impacts Grafana in general, we expect you to report it to Grafana Labs, not to the bug bounty program of us and every other Grafana customer.  We appreciate your commitment to getting security vulnerabilities fixed.\u003c/p\u003e\n\n\u003cp\u003eTo avoid this issue, we recommend concentrating on issues that relate to how Aiven sets up and manages our customers' services, rather than issues with the services in general.  If you could copy the report from somewhere else and paste it into the submission form for our program unchanged, it will most likely be rejected.\u003c/p\u003e\n\n\u003ch3\u003eSimilar Targets\u003c/h3\u003e\n\n\u003cp\u003eBugs that apply in essentially the same way against the following targets are considered one bug, not two.  When equivalent services are in scope for which bugs are presumptively equivalent, we will note those services here.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eAll targets are accessible through the public internet. \u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for a free trial account using your @bugcrowdninja.com email address in any of the targets listed In Scope.  For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. \u003c/p\u003e\n\n\u003cp\u003eWe request that you not create credentials using other email domains.  For example, if you invite another user, that user should be of the form \"yourusername+account2@bugcrowdninja.com\".  In particular, please do not use disposable email addresses.\u003c/p\u003e\n\n\u003ch2\u003eGeneral Information\u003c/h2\u003e\n\n\u003cp\u003eYou may create instances of any of our public services to test against within your account.  You must create the account using your bugcrowdninja.com email address and should only interact with services in aivencloud.com that you created and control.\u003c/p\u003e\n\n\u003cp\u003eThe services can be launched via \u003ca href=\"https://console.aiven.io/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://console.aiven.io/\u003c/a\u003e or using our API at \u003ca href=\"https://api.aiven.io/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://api.aiven.io/\u003c/a\u003e (documentation at \u003ca href=\"https://api.aiven.io/doc/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://api.aiven.io/doc/\u003c/a\u003e).\u003c/p\u003e\n\n\u003cp\u003eWe provide a brief overview of our services here, but the most up to date information will be available at \u003ca href=\"https://docs.aiven.io/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.aiven.io/\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eInformation about Billable Services\u003c/h2\u003e\n\n\u003cp\u003eYou may use a free tier account, or you may use trial credits; if you require additional trial credits, please reach out within the program with a description of your activity, and some can be added to your account.  \u003cstrong\u003ePlease do not use a credit card; expenses will not be reimbursed in case you are billed, and removing your card from our system will take some time\u003c/strong\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003eAiven is particularly concerned with the following threats:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCross-client data access\u003c/li\u003e\n\u003cli\u003eTotal control of another customer's account\u003c/li\u003e\n\u003cli\u003ePivot attacks within Aiven's orchestration plane\u003c/li\u003e\n\u003cli\u003eRemote code execution on services not designed to provide this\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eOnly services you create by yourself - for example, PostgreSQL, Kafka and Grafana - are in-scope. Other services in aivencloud.com domain not created by you are explicitly out of scope, as those are our customers' services.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eFunctionality provided through third parties is out of scope.  This includes Calendly, Qualified, Salesforce, and similar.  In general, functionality like contact us forms, scheduling and booking, interactions with our sales team, and real-time chat functionality will be provided through third parties; before submitting, check whether the domain you are interacting with is hosted by Aiven or a third party.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eThe contact us form (https://aiven.io/contact) and embedded versions of this contact us form on other pages are out of scope. You can identify and ignore them based on the src of the iframe (https://go.aiven.io/l/890043/2022-02-15/7dc33?referrer=contact or similar).\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eRate limiting issues \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eUnreported or very recently reported issues (0day), or issues for which no patch is available, against software not published by Aiven.  The patch must have been out for at least 30 days and \u003cstrong\u003enew\u003c/strong\u003e services created in Aiven must be vulnerable for us to pay a bounty for a known public issue.  For example, an issue in Postgres that was reported publicly only last week will not be eligible for a bounty from our program.  Also note that when such issues are eligible for a bounty, it may be at a reduced rate.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"ac63f02e-eef9-4bb7-b18c-69a4f6a140c9","name":"Database Services Tier 1","targets":[{"id":"a070ba42-2b85-416c-8eff-7e0eaa584d08","uri":"https://aiven.io/clickhouse","name":"Aiven for Clickhouse","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"db24f11b-7f02-4f2c-8277-24e1f4d4d7aa","sortOrder":0},"sortOrder":0,"tags":[{"id":"95db792c-091b-4c81-8d72-b09b1d065f09","name":"Cloud","targetId":"a070ba42-2b85-416c-8eff-7e0eaa584d08"}],"recentChangeFlags":null},{"id":"798491a3-4b8b-40dd-bde9-fdf71081abe1","uri":"https://aiven.io/docs/products/metrics/concepts/metrics-overview","name":"Aiven for Metrics","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1c0b9e6e-5295-4d66-8c84-57eae52d4c0f","sortOrder":0},"sortOrder":0,"tags":[{"id":"95db792c-091b-4c81-8d72-b09b1d065f09","name":"Cloud","targetId":"798491a3-4b8b-40dd-bde9-fdf71081abe1"}],"recentChangeFlags":null},{"id":"4510338f-d64b-44eb-8a79-fcaa8ee53218","uri":"","name":"Aiven for Valkey","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"28f5c31c-e06b-45f9-9a17-53064d465a8f","sortOrder":0},"sortOrder":0,"tags":[{"id":"99bf10d6-2a86-4993-826a-dbf3a956aefa","name":"Redis","targetId":"4510338f-d64b-44eb-8a79-fcaa8ee53218"}],"recentChangeFlags":null},{"id":"6743df92-0638-4d1e-8b1d-ec8535a28c3e","uri":"","name":"Aiven for Apache Kafka","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"bfb2417f-2b62-4180-8ca0-72c3be3bcc35","sortOrder":3},"sortOrder":3,"tags":[{"id":"515aada9-3b1a-4e38-a3f2-a9abd77feb0b","name":"Apache Kafka","targetId":"6743df92-0638-4d1e-8b1d-ec8535a28c3e"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"89ac7646-f653-46f1-a65a-2157827fde5e","p1MaxCents":2310000,"p1MinCents":1650000,"p2MaxCents":1320000,"p2MinCents":528000,"p3MaxCents":462000,"p3MinCents":165000,"p4MaxCents":99000,"p4MinCents":66000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003e\u003cstrong\u003eAiven for Clickhouse\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eSee \u003ca href=\"https://aiven.io/clickhouse\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://aiven.io/clickhouse\u003c/a\u003e for details about the service.\u003c/p\u003e\n\n\u003cp\u003eAiven for ClickHouse is powered by ClickHouse, a highly scalable, open source database that uses a column-oriented structure. \u003c/p\u003e\n\n\u003cp\u003eClickHouse is designed for online analytical processing (OLAP) applications, and is an ideal tool for applications such as web analytics, or complex data reporting.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAiven for Metrics\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eSee \u003ca href=\"https://aiven.io/docs/products/metrics/concepts/metrics-overview\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://aiven.io/docs/products/metrics/concepts/metrics-overview\u003c/a\u003e for details about the service.\u003c/p\u003e\n\n\u003cp\u003eAiven for Metrics is a managed service that provides a Prometheus service for storing and querying service metrics information.  It is essentially an implementation of Thanos.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAiven for Valkey\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eSee \u003ca href=\"https://aiven.io/valkey\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://aiven.io/valkey\u003c/a\u003e for details about the service.\u003c/p\u003e\n\n\u003cp\u003eAiven for Valkey is an in-memory database using the open-source project \u003ca href=\"https://valkey.io/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://valkey.io/\u003c/a\u003e.  It is often used for queueing and caching, and is an alternative to Redis.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAiven for Apache Kafka\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eSee \u003ca href=\"https://aiven.io/kafka\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://aiven.io/kafka\u003c/a\u003e for details about the service. Also in scope are Aiven for Apache Kafka Connect \u003ca href=\"https://aiven.io/kafka-connect\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://aiven.io/kafka-connect\u003c/a\u003e and Aiven for Apache Kafka MirrorMaker 2 \u003ca href=\"https://aiven.io/mirrormaker\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://aiven.io/mirrormaker\u003c/a\u003e.  These services can be added to a Kafka service in your account.\u003c/p\u003e\n\n\u003cp\u003eAiven for Apache Kafka® is a fully managed streaming platform, deployable in the cloud of your choice. Snap it into your existing workflows with the click of a button, automate away the mundane tasks, and focus on building your core apps.\u003c/p\u003e\n\n\u003cp\u003eAiven offers a REST API for Kafka governance which is within the scope of this bounty tier.  See \u003ca href=\"https://aiven.io/docs/products/kafka/concepts/governance-overview\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://aiven.io/docs/products/kafka/concepts/governance-overview\u003c/a\u003e for more information.\u003c/p\u003e","rewardRangeData":{"1":{"min":16500,"max":23100},"2":{"min":5280,"max":13200},"3":{"min":1650,"max":4620},"4":{"min":660,"max":990},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"249382c5-fd00-46ab-b65a-ded0149d71e9","name":"Database Services Tier 2","targets":[{"id":"27ab3402-aa4a-4e09-a03d-821ee01697ad","uri":"","name":"Aiven for OpenSearch","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b4e19035-28ab-444e-b6de-6ca1509a5666","sortOrder":1},"sortOrder":1,"tags":[{"id":"30a3c3f4-5f27-4be7-9e4f-5fe8e80828f8","name":"Elasticsearch","targetId":"27ab3402-aa4a-4e09-a03d-821ee01697ad"}],"recentChangeFlags":null},{"id":"fd4e19a5-883b-44ae-a797-fd9b422a5dd5","uri":"","name":"Aiven for Grafana","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a948926b-4fe9-4aeb-8248-c325db6b20d4","sortOrder":2},"sortOrder":2,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"fd4e19a5-883b-44ae-a797-fd9b422a5dd5"}],"recentChangeFlags":null},{"id":"42ace869-3533-4a74-ac81-ffefd5ac78f9","uri":"","name":"Aiven for PostgreSQL","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"fa51d5ec-52ec-41f1-9cc2-477e8c054321","sortOrder":5},"sortOrder":5,"tags":[{"id":"95cf953e-85ee-42c2-9123-09d81bfe7ba9","name":"PostgreSQL","targetId":"42ace869-3533-4a74-ac81-ffefd5ac78f9"}],"recentChangeFlags":null},{"id":"5bfc8fca-0ad8-4679-bba3-9d6e77b684f5","uri":"","name":"Aiven for MySQL","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d30c9bf9-ecc3-4711-8c3c-5415232557bd","sortOrder":7},"sortOrder":7,"tags":[{"id":"5644ab16-c7ca-4ff7-ac95-383343dab77f","name":"MySQL","targetId":"5bfc8fca-0ad8-4679-bba3-9d6e77b684f5"}],"recentChangeFlags":null},{"id":"3a67beb1-540a-4159-9121-ac0d2642973f","uri":"https://regatta.aiven.io/","name":"regatta.aiven.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"df76f116-ffeb-49f2-b5b5-ecf9aeb88915","sortOrder":10},"sortOrder":10,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"17cfe949-8fb6-4294-a52f-35c8cc1765f4","p1MaxCents":1500000,"p1MinCents":1000000,"p2MaxCents":750000,"p2MinCents":350000,"p3MaxCents":250000,"p3MinCents":100000,"p4MaxCents":65000,"p4MinCents":40000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003e\u003cstrong\u003eAiven for PostgreSQL\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eSee \u003ca href=\"https://aiven.io/postgresql\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://aiven.io/postgresql\u003c/a\u003e for details about the service.\u003c/p\u003e\n\n\u003cp\u003eAiven for PostgreSQL is a fully managed SQL database, deployable in the cloud of your choice. Snap it into your existing workflows with the click of a button, automate away the mundane tasks, and focus on building your core apps.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAiven for MySQL\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eSee \u003ca href=\"https://aiven.io/mysql\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://aiven.io/mysql\u003c/a\u003e for details about the service.\u003c/p\u003e\n\n\u003cp\u003eAiven for MySQL is a fully managed SQL database, deployable in the cloud of your choice. Snap it into your existing workflows with the click of a button, automate away the mundane tasks, and focus on building your core apps.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAiven for OpenSearch\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eSee \u003ca href=\"https://aiven.io/opensearch\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://aiven.io/opensearch\u003c/a\u003e for details about the service.\u003c/p\u003e\n\n\u003cp\u003eAiven for OpenSearch is a fully managed search and analytics suite forked from Elasticsearch, and deployable in the cloud of your choice. \u003c/p\u003e\n\n\u003cp\u003eNote that Aiven for OpenSearch has \u003cstrong\u003etwo\u003c/strong\u003e access control models for customers to select from.  It is possible to manage security through the Aiven Console, or through OpenSearch native security management.  The models are distinct, and in some cases it may be possible for users making either choice to configure OpenSearch in ways that might not be allowed in the Aiven console.  Using option 1, access control on the Aiven console, it is intentionally possible that developers having the avnadmin user can make any change to the service.  See \u003ca href=\"https://aiven.io/docs/products/opensearch/concepts/access_control\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://aiven.io/docs/products/opensearch/concepts/access_control\u003c/a\u003e for more information.\u003c/p\u003e\n\n\u003cp\u003eNote: Using the access control feature, ACLs apply only to indices and do not control access to other OpenSearch APIs, including OpenSearch Dashboards.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAiven for Grafana\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eSee \u003ca href=\"https://aiven.io/grafana\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://aiven.io/grafana\u003c/a\u003e for details about the service.\u003c/p\u003e\n\n\u003cp\u003eAiven for Grafana is a fully managed analytics and monitoring solution, deployable in the cloud of your choice. Snap it into your existing workflows with the click of a button, automate away the mundane tasks, and focus on building your core apps.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eRegatta\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eRegatta is an internal application at Aiven.  The Okta system is out of scope; however, we are interested in anything that demonstrably grants unauthorized access to the application.  Please do not report cookie or header related issues or other \u0026quot;best practice\u0026quot; items unless you can demonstrate unauthorized access.\u003c/p\u003e","rewardRangeData":{"1":{"min":10000,"max":15000},"2":{"min":3500,"max":7500},"3":{"min":1000,"max":2500},"4":{"min":400,"max":650},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"07e84191-de46-45af-a66a-310e7dcc7ec9","name":"In Scope (Website Console)","targets":[{"id":"172db4ed-3e91-48e3-88c5-1f1898c34006","uri":"https://aiven.io/","name":"aiven.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"cc5ecdcc-0f06-4967-bea1-003b713aeab6","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"172db4ed-3e91-48e3-88c5-1f1898c34006"}],"recentChangeFlags":null},{"id":"78bb623f-02f3-487b-b878-9d0e679bdf49","uri":"https://console.aiven.io/login","name":"console.aiven.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8cfe7ee7-62dc-4bc2-8e08-c113225e3d3b","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"78bb623f-02f3-487b-b878-9d0e679bdf49"}],"recentChangeFlags":null},{"id":"c578b952-5180-49f9-b1d6-a98dc0f64624","uri":"https://api.aiven.io/login","name":"api.aiven.io","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8b2d4e5d-ea56-41dd-a085-bd915a54bc7d","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"c578b952-5180-49f9-b1d6-a98dc0f64624"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"c578b952-5180-49f9-b1d6-a98dc0f64624"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"c578b952-5180-49f9-b1d6-a98dc0f64624"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":{"id":"86b07e5e-68fa-42c5-bf2f-aa329d138999","p1MaxCents":450000,"p1MinCents":410000,"p2MaxCents":175000,"p2MinCents":150000,"p3MaxCents":85000,"p3MinCents":60000,"p4MaxCents":25000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eTarget Information\u003c/h2\u003e\n\n\u003cp\u003ePlease be aware of the following two key points regarding \u003ca href=\"https://console.aiven.io\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003econsole.aiven.io\u003c/a\u003e, to avoid spending your time on an informational or unreproducible submission:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAPI operations invoked by the console are authenticated using the aivenv1 token in the \u003ccode\u003eAuthorization:\u003c/code\u003e header, not the browser cookies; if you copy the authorization header from a request made by a user, the operation will be performed as that user and this is not a bug.\u003c/li\u003e\n\u003cli\u003eThe primary purpose of the Aiven console is for our customers to administer their services with us.  Users can, and nearly all users do, grant credentials and access to services that they create to principals that may not even have a user in the Aiven console.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eNote also that https://aiven.io is hosted by fly.io.  We are aware that fly.io has a network configuration that makes some scanners claim ports are open which are not.  Also, vulnerabilities that would affect any fly.io site should be reported to fly.io and not to this program.  We are particularly interested only in those vulnerabilities in https://aiven.io that can affect https://console.aiven.io or https://api.aiven.io, or that allow for defacement or code injection into https://aiven.io.\u003c/p\u003e","rewardRangeData":{"1":{"min":4100,"max":4500},"2":{"min":1500,"max":1750},"3":{"min":600,"max":850},"4":{"min":200,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"6de2f628-b150-442c-8234-7577fa383bce","name":"Aiven Open Source Repositories","targets":[{"id":"44595699-389b-46ed-b4db-642880cb4af2","uri":"https://github.com/Aiven-Open","name":"github.com/Aiven-Open","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a08a7ab1-32c0-4fd7-af42-a5187edf18b1","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"3c21c4e8-9909-4b58-a444-f579c47a7664","uri":"https://github.com/Aiven","name":"github.com/Aiven","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e4751ab9-e043-41d2-b15a-9010bbda9314","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":3,"description":null,"rewardRange":{"id":"991f9d0e-799f-443d-902e-fe02a0358c26","p1MaxCents":150000,"p1MinCents":100000,"p2MaxCents":100000,"p2MinCents":50000,"p3MaxCents":50000,"p3MinCents":25000,"p4MaxCents":25000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eVulnerabilities in Aiven open source code.\u003c/p\u003e\n\n\u003cp\u003eIf a repository is forked from another repository, and the vulnerability is also present in the repository it\u0026#39;s forked from, it is not eligible for a bounty; we recommend submitting to upstream.\u003c/p\u003e","rewardRangeData":{"1":{"min":1000,"max":1500},"2":{"min":500,"max":1000},"3":{"min":250,"max":500},"4":{"min":50,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"f16d3fce-20c5-4c56-818c-3f01caec2a1b","name":"Capture the Flag Challenge","targets":[{"id":"bbd6c3eb-2b45-4316-a705-ca7031de1faa","uri":"http://falcon-bug-bounty-flag-pgsql-dev-sandbox.e.aivencloud.com/","name":"falcon-bug-bounty-flag-pgsql-dev-sandbox.e.aivencloud.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"80b3abf7-4ed1-42aa-a8fa-d66a22bce841","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":4,"description":null,"rewardRange":{"id":"4dda580c-3145-411a-86fc-e2e96384c013","p1MaxCents":2500000,"p1MinCents":2500000,"p2MaxCents":null,"p2MinCents":null,"p3MaxCents":null,"p3MinCents":null,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eInclude in your report the following items:\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eThe complete contents of \u003ccode\u003e/etc/ssh/ssh_host_ed25519_key\u003c/code\u003e, i.e. the server\u0026#39;s SSH host private ed25519 key, current as at the time of exploitation\u003c/li\u003e\n\u003cli\u003eThe current external IP address of the host\u003c/li\u003e\n\u003cli\u003eAn explanation of how you got the key\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003ePlease do not submit the server\u0026#39;s public key or your own machine\u0026#39;s SSH private key.\u003c/p\u003e","rewardRangeData":{"1":{"min":25000,"max":25000},"2":{"min":null,"max":null},"3":{"min":null,"max":null},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"2e20fb55-2b63-4297-bd7d-dcf17714c3bc","name":"Out of Scope ","targets":[{"id":"3ffdeda7-39ab-4aba-ab7c-cc63e9f3270c","uri":"","name":"aquarium.aiven.io\t","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"bdd59cf7-1358-4054-a253-7cf54e440eff","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"fef78863-cf47-42d7-90fb-7934e9abeade","uri":"","name":"uptime.aiven.io\t","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c2061fc6-8a05-4fda-8c11-f87a15e6520d","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"60dcfa75-1241-4f80-82a5-5ff081376f6b","uri":"","name":"video.aiven.io\t","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"84a937d4-dfba-4783-9baf-7b29c3cffec5","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"8a490409-65b1-49b8-a80e-538ec0b1b4ef","uri":"","name":"aiven.io/community","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c304636f-68a3-4090-897b-64854b3da52a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"6f7ab9fb-6eaa-4d37-82b1-63f7d80f2984","uri":"","name":"aiven.io/contact","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f051c508-5abb-4014-b475-6141b09c055b","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"26cb3216-6084-4063-9ee1-6927a2428c25","uri":"","name":"Customer services you did not create","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"06971184-e7d0-454a-b55f-018f4ff8ac9a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"f165f4ed-45ad-4583-ad45-3c6b84a3ecce","uri":"","name":"*.aiven.fi","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b0276048-d8aa-41e7-a405-14078f75d3a9","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"6a178be2-1bce-421c-9f2f-af3d171fbc3f","uri":"","name":"github.com/Aiven-Labs","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9ccfea6a-c241-42e2-bd6d-799c0c790c0b","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"46365346-7972-4658-abdf-e8ca8a577204","uri":"","name":"*.avns.net","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"03cf41df-d23c-4d3e-9285-fa7917b7526d","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"aa9178ef-1027-4b1e-af82-c422d24501ba","uri":"","name":"events.aiven.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"18a2ec4a-9e8e-462a-abf7-7640121b3570","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"54c9900e-b7b3-4f1a-848c-714cb842fb09","uri":"","name":"ideas.aiven.io","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"665ad82a-6cfd-4977-b071-7212d3b6c4b9","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"dcc1a24c-a110-405c-974f-1634db783c75","uri":"","name":"aivenhelp.zendesk.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5f25dc29-e189-483d-8939-37d66566bdc5","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"199356d8-c028-4f67-bb37-d40997e152ab","uri":"","name":"support.aiven.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c2f3cb7a-9bfa-4eee-8a4f-51afc7d40318","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"c7c5a195-70fd-4750-94f2-252f6cd16cf3","uri":"","name":"Creation of support tickets","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"914f7e84-c194-4c18-8eb9-ba775ae2f9ed","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":5,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eIn general, services hosted for Aiven by third parties are out of scope.  Aiven\u0026#39;s test environment is also out of scope.  This group provides a partial list of targets for which reports will not be accepted by our program.\u003c/p\u003e\n\n\u003cp\u003eMost subdomains of Aiven that are not specifically marked in scope are hosted by a third party.  Please check who is hosting the service, if possible, before submitting your bug.\u003c/p\u003e\n\n\u003cp\u003eServices created by customers are generally within the aivencloud.com domain.  If you did not create the service, and it is not specifically identified here as a challenge target, you may not perform testing against it.  We suggest creating a service within your own account to perform this testing.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"46e74599-e82c-4688-ad58-c881d3a29ab8","name":"Third-Party Dependency Versions","targets":[{"id":"664cccc4-819b-418e-b7e7-ae8f2017a0db","uri":"","name":"Third-party dependency versions","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"cbc267fd-ec87-4e43-9b0b-f11efa24a4dd","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":6,"description":null,"rewardRange":{"id":"f8523db8-907f-4203-98dc-bc19b98ec609","p1MaxCents":100000,"p1MinCents":75000,"p2MaxCents":75000,"p2MinCents":50000,"p3MaxCents":50000,"p3MinCents":25000,"p4MaxCents":25000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eFor this group, refer to the rest of the brief for in-scope assets and limitations.  We limit the total payout for reports that show only that Aiven exposes a vulnerability in a third-party dependency.  Do not use this tier for vulnerabilities that are primarily due to Aiven\u0026#39;s code or deployment model.\u003c/p\u003e\n\n\u003cp\u003eBe aware that Aiven conducts software composition analysis internally and reports of this type may be duplicates of internal findings.\u003c/p\u003e","rewardRangeData":{"1":{"min":750,"max":1000},"2":{"min":500,"max":750},"3":{"min":250,"max":500},"4":{"min":50,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"b71f4ed8-40a6-40fe-81e7-c13f04b2b634","name":"Aiven Runtime","targets":[{"id":"49724871-ea49-4bd0-9796-5c6c153cdb8b","uri":"https://aiven.io/runtime","name":"Aiven Runtime","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4c4b4c90-59ba-4f5d-bd0f-e02e81596d06","sortOrder":0},"sortOrder":0,"tags":[{"id":"95db792c-091b-4c81-8d72-b09b1d065f09","name":"Cloud","targetId":"49724871-ea49-4bd0-9796-5c6c153cdb8b"}],"recentChangeFlags":["entirely_new"]}],"inScope":false,"sortOrder":7,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eAiven Runtime is an application development platform for containerized applications that run alongside databases.  Read about it at https://aiven.io/docs/products/runtime.\u003c/p\u003e\n\n\u003cp\u003eRuntime is not yet in scope for the bug bounty program.  We will update this page when it is.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"89ce5856-4e0d-4d5f-8151-55575aeddbd5","code":"aiven-mbb-og","state":"in_progress","endsAt":null,"bountyId":"0715f39c-df8f-4a6d-9eed-2271a72f210b","startsAt":"2023-08-24T18:00:00Z"},"vrtScopeRules":[{"id":"e05217db-6eca-4a7b-8c61-38b6ff26dbea","notes":"","targets":[],"vrtIds":{"categories":[{"id":"application_level_denial_of_service_dos","version":"1.18"}]},"allTargets":true,"targetGroups":[],"exclusionType":"out_of_scope"},{"id":"4f546ba8-8db1-4cda-982e-7576c0805623","notes":"","targets":[],"vrtIds":{"categories":[{"id":"physical_security_issues","version":"1.18"}]},"allTargets":true,"targetGroups":[],"exclusionType":"out_of_scope"},{"id":"ccc08399-7fd1-46c6-862a-136c799d0f7d","notes":"Where the operations allowed in the web interface and the API differ, it is the API that is considered authoritative.","targets":[{"id":"172db4ed-3e91-48e3-88c5-1f1898c34006","name":"aiven.io"},{"id":"78bb623f-02f3-487b-b878-9d0e679bdf49","name":"console.aiven.io"},{"id":"c578b952-5180-49f9-b1d6-a98dc0f64624","name":"api.aiven.io"}],"vrtIds":{"categories":[{"id":"broken_access_control","version":"1.19.1"}]},"allTargets":false,"targetGroups":[{"id":"07e84191-de46-45af-a66a-310e7dcc7ec9","name":"In Scope (Website Console)"}],"exclusionType":"conditional"}],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/2f7a/aeda/2c3bd592/5f27709d4d0c543665a7d1fa0bb2bc9f_1656939875704.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-03-19T11:32:06.433Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/aiven-mbb-og","changelogs":"/engagements/aiven-mbb-og/changelog","submissions":null,"announcements":"/engagements/aiven-mbb-og/announcements","hallOfFame":"/engagements/aiven-mbb-og/hall_of_fames","crowdstream":"/engagements/aiven-mbb-og/crowdstream"},"announcementsCount":14,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/aiven-mbb-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":"updated","userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=aiven-mbb-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/aiven-mbb-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/aiven-mbb-og/changelog","publishedAt":"2026-09-28T20:46:08.739Z","engagementChangelogUrl":"/engagements/aiven-mbb-og/changelog/326ffefd-402d-4c50-a6c5-490f1286413a","createUserFeedbacksUrl":"/engagements/aiven-mbb-og/feedbacks","engagementCrowdstreamUrl":"/engagements/aiven-mbb-og/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[{"id":"e05217db-6eca-4a7b-8c61-38b6ff26dbea","vrt_ids":{"categories":[{"id":"application_level_denial_of_service_dos","lineage":"Application-Level Denial-of-Service (DoS)","version":"1.18"}]},"targets":[],"target_groups":[],"exclusion_type":"out_of_scope","notes":"","all_targets":true},{"id":"4f546ba8-8db1-4cda-982e-7576c0805623","vrt_ids":{"categories":[{"id":"physical_security_issues","lineage":"Physical Security Issues","version":"1.18"}]},"targets":[],"target_groups":[],"exclusion_type":"out_of_scope","notes":"","all_targets":true},{"id":"ccc08399-7fd1-46c6-862a-136c799d0f7d","vrt_ids":{"categories":[{"id":"broken_access_control","lineage":"Broken Access Control (BAC)","version":"1.19.1"}]},"targets":[{"id":"172db4ed-3e91-48e3-88c5-1f1898c34006","name":"aiven.io"},{"id":"78bb623f-02f3-487b-b878-9d0e679bdf49","name":"console.aiven.io"},{"id":"c578b952-5180-49f9-b1d6-a98dc0f64624","name":"api.aiven.io"}],"target_groups":[{"id":"07e84191-de46-45af-a66a-310e7dcc7ec9","name":"In Scope (Website Console)","target_ids":[]}],"exclusion_type":"conditional","notes":"Where the operations allowed in the web interface and the API differ, it is the API that is considered authoritative.","all_targets":false}]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}