{"id":"ad976c03-b976-410d-bd0a-5d76d56b9477","engagementId":"f499f4ab-ad05-46e4-9ddc-984be61cf511","data":{"brief":{"id":"a745b36a-c340-45d6-9d2c-8abe65c88c21","name":"Asana","tagline":"We're empowering teams to do great things together.","description":"\u003cp\u003eNo technology is perfect and Asana believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher in order to identify weaknesses. If you believe you've found a security issue, we encourage you to notify us. We welcome working with you to resolve the issue promptly.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eLikelihood = How likely this particular vulnerability is to be uncovered and exploited by an attacker?\u003cbr\u003e\nImpact = Technical impact + Business impact. The first is the “technical impact” on the application, the data it uses, and the functions it provides. The other is the “business impact” on the business and company operating the application. See \u003ca href=\"https://owasp.org/www-community/OWASP_Risk_Rating_Methodology\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eOWASP methodology for risk rating\u003c/a\u003e as a reference.\u003c/p\u003e\n\n\u003cp\u003eAsana uses a nonce based CSP policy. If you discover an XSS vulnerability that you cannot exploit due to the CSP policy, but would at least be a P4 without the CSP policy present, we will reward that vulnerability as if it was a P4.\u003c/p\u003e\n\n\u003ch3\u003ePlease also include the following information in your submission (if applicable):\u003c/h3\u003e\n\n\u003cp\u003eDomain Type (organization/workspace)\u003cbr\u003e\nDomain ID(s) used\u003cbr\u003e\nDomain Tier (free/premium/business/enterprise)\u003cbr\u003e\nAttacker membership level(s)\u003cbr\u003e\nVictim membership level(s)\u003cbr\u003e\nSecurity Impact\u003cbr\u003e\nEmails of accounts used for testing\u003c/p\u003e\n\n\u003ch3\u003eSpecial note on prompt injection\u003c/h3\u003e\n\n\u003cp\u003eWe will consider submissions of this type if you can manipulate AI to have a measurable security impact to Asana, not just manipulating the AI model. \u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003chr\u003e\n\n\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cp\u003eAsana helps teams organize and manage all their work in the form of different projects. Please refer to the credentials section to understand how to sign up and go through the onboarding workflow to create one such project/workspace.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003ePermissions overview\u003c/strong\u003e\u003cbr\u003e\n\u003ca href=\"https://help.asana.com/hc/en-us/articles/17826920767259-Permissions-overview\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://help.asana.com/hc/en-us/articles/17826920767259-Permissions-overview\u003c/a\u003e\u003cbr\u003e\n\u003cstrong\u003eHelp articles\u003c/strong\u003e\u003cbr\u003e\n\u003ca href=\"https://help.asana.com/hc/en-us/sections/14005484724635-Permissions\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://help.asana.com/hc/en-us/sections/14005484724635-Permissions\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://help.asana.com/hc/en-us\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://help.asana.com/hc/en-us\u003c/a\u003e\u003cbr\u003e\n\u003cstrong\u003eDeveloper Documentation\u003c/strong\u003e\u003cbr\u003e\n\u003ca href=\"https://developers.asana.com/docs\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://developers.asana.com/docs\u003c/a\u003e \u003cbr\u003e\n\u003cstrong\u003eAPI Documentation\u003c/strong\u003e\u003cbr\u003e\n\u003ca href=\"https://developers.asana.com/docs\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://developers.asana.com/docs\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://developers.asana.com/docs/app-components\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://developers.asana.com/docs/app-components\u003c/a\u003e\u003cbr\u003e\n\u003cstrong\u003eAsana Academy\u003c/strong\u003e\u003cbr\u003e\n\u003ca href=\"https://academy.asana.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://academy.asana.com/\u003c/a\u003e\u003cbr\u003e\n\u003cstrong\u003eOther helpful resources\u003c/strong\u003e\u003cbr\u003e\n\u003ca href=\"https://help.asana.com/hc/en-us/articles/14075208738587-Premium-Business-and-Enterprise-authentication\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://help.asana.com/hc/en-us/articles/14075208738587-Premium-Business-and-Enterprise-authentication\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://help.asana.com/hc/en-us/articles/14139896860955-Privacy-and-security\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://help.asana.com/hc/en-us/articles/14139896860955-Privacy-and-security\u003c/a\u003e \u003cbr\u003e\n\u003ca href=\"https://asana.com/features/admin-security/admin-console\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://asana.com/features/admin-security/admin-console\u003c/a\u003e \u003cbr\u003e\n\u003ca href=\"https://asana.com/product/ai\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://asana.com/product/ai\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://help.asana.com/s/article/ai-studio\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://help.asana.com/s/article/ai-studio\u003c/a\u003e\u003c/p\u003e\n\n\u003ch2\u003eCredentials:\u003c/h2\u003e\n\n\u003cp\u003ePlease self sign up for a free account using your @bugcrowdninja.com email address at \u003ca href=\"https://asana.com/create-account\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://asana.com/create-account\u003c/a\u003e. This process will automatically get you a free 30 day trial of Asana's Premium/Business accounts, without needing to input your credit card information. \u003cbr\u003e\nIf you would like to continue using a premium account for testing after the trial ends, please create a new account using username+1@bugcrowdninja.com, etc.\u003c/p\u003e\n\n\u003ch1\u003eOut of Scope (PLEASE READ)\u003c/h1\u003e\n\n\u003chr\u003e\n\n\u003cul\u003e\n\u003cli\u003eassets.asana.biz\u003c/li\u003e\n\u003cli\u003eAny testing involving making repetitive network requests. This includes testing for denial of service attacks and testing to \nsee if rate limits are properly in place.\u003c/li\u003e\n\u003cli\u003eSubmitting any form on form.asana.com or form-beta.asana.biz that you did not create yourself. This includes submitting any customer survey hosted on those domains.\u003c/li\u003e\n\u003cli\u003eAny Jira instance hosted on a subdomain of integrations.asana.plus. For example, jira-prod.integrations.asana.plus would be out of scope but foo.integrations.asana.plus would be in scope.\u003c/li\u003e\n\u003cli\u003eIf you find credentials, including but not limited to Asana logins, Okta logins, etc please report them but DO NOT attempt to log in. We will validate on our end.\u003c/li\u003e\n\u003cli\u003eSubmissions only containing leaked passwords, access tokens, etc will be accepted and rewarded with \u003cstrong\u003epoints only\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eSubmissions only containing leaked documents, files etc will be accepted and rewarded with \u003cstrong\u003epoints only\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eSubmissions only containing only broken links, or links pointing to unowned domains in documentation or static asana websites with no \nfurther impact will be accepted and rewarded with \u003cstrong\u003epoints only\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eHTTP 404 codes/pages or other HTTP non-200 codes/pages.\u003c/li\u003e\n\u003cli\u003eFingerprinting / banner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eDisclosure of known public files or directories, (e.g. robots.txt).\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eSecurity best practices without evidence of security impact or exploitation\u003c/li\u003e\n\u003cli\u003eWeak login/signup without evidence of security impact or exploitation\u003c/li\u003e\n\u003cli\u003eWeak password policy without demonstrated impact or exploitation\u003c/li\u003e\n\u003cli\u003eCookie issues without evidence of security impact or exploitation\u003c/li\u003e\n\u003cli\u003eLack of Secure/HTTPOnly flags on non-sensitive Cookies.\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers, specifically \u003ca href=\"https://www.owasp.org/index.php/List_of_useful_HTTP_headers\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://www.owasp.org/index.php/List_of_useful_HTTP_headers\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003ePublicly-known zero-day vulnerabilities will not be considered for eligibility until more than 30 days have passed since patch availability\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g. Stack Traces, application or server errors).\u003c/li\u003e\n\u003cli\u003eEXIF data not being stripped from files or attachments.\u003c/li\u003e\n\u003cli\u003eAttacks that aim to destroy or corrupt data not belonging to you.\u003c/li\u003e\n\u003cli\u003eAttacks attempting to extend trial licenses.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIntentional access to data or information not belonging to you beyond the minimum necessary to demonstrate the vulnerability.\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDo not access or manipulate data outside of domains that you control (including but not limited to customer data).\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eOut of scope for Enterprise Technology targets:\u003c/h1\u003e\n\n\u003cul\u003e\n\u003cli\u003eClickjacking\u003c/li\u003e\n\u003cli\u003eBroken link hijacking\u003c/li\u003e\n\u003cli\u003eFirebase API key leakage without demonstrated impact\u003c/li\u003e\n\u003cli\u003eSession expiration after logout\u003c/li\u003e\n\u003cli\u003eSession timeout lengths or account lockout policies\u003c/li\u003e\n\u003cli\u003eFailure to Invalidate Session on Password Reset\u003c/li\u003e\n\u003cli\u003eUsage of components with known vulnerabilities without demonstrated security impact\u003c/li\u003e\n\u003cli\u003eBusiness logic issues without demonstrated security impact\u003c/li\u003e\n\u003cli\u003eUnrestricted file upload without demonstrated security impact\u003c/li\u003e\n\u003cli\u003eLeakage/disclosure of Google Maps/MapBox API keys\u003c/li\u003e\n\u003cli\u003eExternal service interaction without demonstrated security impact\u003c/li\u003e\n\u003cli\u003ePassword complexity and password length issues\u003c/li\u003e\n\u003cli\u003ePost-based XSS without demonstrated security impact\u003c/li\u003e\n\u003cli\u003eBlind SSRF without demonstrated security impact.\u003c/li\u003e\n\u003cli\u003eSelf-XSS without demonstrated security impact\u003c/li\u003e\n\u003cli\u003eCross-site request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions\u003c/li\u003e\n\u003cli\u003eAttacks requiring MITM or physical access to a user's device.\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without a working Proof of Concept.\u003c/li\u003e\n\u003cli\u003eComma Separated Values (CSV) injection without demonstrating a vulnerability.\u003c/li\u003e\n\u003cli\u003eMissing best practices in SSL/TLS configuration.\u003c/li\u003e\n\u003cli\u003eContent spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS\u003c/li\u003e\n\u003cli\u003eRate limiting or brute force issues\u003c/li\u003e\n\u003cli\u003eMissing best practices in Content Security Policy.\u003c/li\u003e\n\u003cli\u003eMissing HttpOnly or Secure flags on cookies\u003c/li\u003e\n\u003cli\u003eMissing email best practices (Invalid, incomplete, or missing SPF/DKIM/DMARC records, etc.)\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\u003c/li\u003e\n\u003cli\u003eSoftware version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors).\u003c/li\u003e\n\u003cli\u003ePublic Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case-by-case basis.\u003c/li\u003e\n\u003cli\u003eTabnabbing\u003c/li\u003e\n\u003cli\u003eIssues that require unlikely user interaction\u003c/li\u003e\n\u003cli\u003eHTML Injection without demonstrated security impact\u003c/li\u003e\n\u003cli\u003eCRLF Injection without demonstrated security impact\u003c/li\u003e\n\u003cli\u003eReports from automated scanners\u003c/li\u003e\n\u003cli\u003eAny activity that could lead to the disruption of our service (DDoS/DoS)\u003c/li\u003e\n\u003cli\u003eCache poisoning without demonstrated security impact\u003c/li\u003e\n\u003cli\u003eRobots.txt or Sitemap.xml without demonstrated security impact\u003c/li\u003e\n\u003cli\u003eInformation Disclosure FrontPage Configuration Information without demonstrated security impact\u003c/li\u003e\n\u003cli\u003eUser/email enumeration\u003c/li\u003e\n\u003cli\u003eClear text password over HTTP without demonstrated security impact\u003c/li\u003e\n\u003cli\u003eDependency confusion\u003c/li\u003e\n\u003cli\u003eEXIF Geolocation Data Not Stripped From Uploaded Images/Documents\u003c/li\u003e\n\u003cli\u003eWordPress user's disclosure/enumeration\u003c/li\u003e\n\u003cli\u003eImproper Cache-Control\u003c/li\u003e\n\u003cli\u003eEnabled WordPress xmlrpc.php\u003c/li\u003e\n\u003cli\u003eOpen redirect without demonstrated security impact\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRole Based Access Control Issues - Can a \u003ccode\u003elimited access member\u003c/code\u003e gain access to projects, areas of the app that they shouldn't have access to?\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eUsers permissions are gated by their effective access level. (i.e. Viewers should not be able to comment)\u003c/li\u003e\n\u003cli\u003e Users should not be able to elevate their own access levels on an object.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAsana as an OAuth provider (\u003ca href=\"https://app.asana.com/-/oauth_authorize\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://app.asana.com/-/oauth_authorize\u003c/a\u003e)\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOAuth vulnerabilities in integrations built into Asana\u003c/li\u003e\n\u003cli\u003eAsana-made Integrations which can be found on \u003ca href=\"https://asana.com/apps?category=made-by-asana\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ethis page\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eApp components \u003ca href=\"https://developers.asana.com/docs/app-components\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eused by some of our integrations\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdmin enforcements cannot be bypassed by internal DomainUsers. \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eFor example when domain is enterprise and is using SAML or GSSO required, we want to make sure all internal members of those domain cannot bypass admin's setting during login or signup.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://help.asana.com/hc/en-us/articles/14139896860955-Privacy-and-security\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://help.asana.com/hc/en-us/articles/14139896860955-Privacy-and-security\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://asana.com/features/admin-security/admin-console\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://asana.com/features/admin-security/admin-console\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as In-Scope. Any domain/property of Asana not listed in the targets section is out of scope. This includes any/all subdomains not listed above.  If you happen to identify a security vulnerability on a target that is not in-scope, but that demonstrably belongs to Asana, it may be reported to this program, and is appreciated - but will ultimately be marked as ‘not applicable’ and will not be eligible for monetary or points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"e656c7da-626f-485f-ab99-6ff92903800f","name":"Asana Targets","targets":[{"id":"7a6acdec-5495-4ed4-bc3f-ec74c4326b75","uri":"https://app.asana.com","name":"app.asana.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5605c7a4-b995-47b1-80eb-f1c52a1b6581","sortOrder":0},"sortOrder":0,"tags":[{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"7a6acdec-5495-4ed4-bc3f-ec74c4326b75"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"7a6acdec-5495-4ed4-bc3f-ec74c4326b75"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7a6acdec-5495-4ed4-bc3f-ec74c4326b75"}],"recentChangeFlags":null},{"id":"2529bfe4-d894-498a-b7ac-8903470fbdea","uri":"https://asana.com","name":"asana.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"75d8a6d7-c503-42db-bc32-15c8b34af765","sortOrder":0},"sortOrder":0,"tags":[{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"2529bfe4-d894-498a-b7ac-8903470fbdea"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"2529bfe4-d894-498a-b7ac-8903470fbdea"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2529bfe4-d894-498a-b7ac-8903470fbdea"}],"recentChangeFlags":null},{"id":"44269153-5846-45a5-a4b8-3d9200fc486a","uri":"https://asana.com/apps?category=made-by-asana","name":"*.asana.plus","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"35460dd6-2e28-4882-8696-6f29b7ab9d18","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"a87d7944-7b19-4c63-bfd0-cfaeadeb7864","uri":"https://asana.com/download","name":"Asana Desktop App","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f43dd790-42ea-41a3-ac9f-bb912a7b8e44","sortOrder":0},"sortOrder":0,"tags":[{"id":"fc8162a2-8e37-4a27-8cbd-3b40e7799f4e","name":"Desktop Application Testing","targetId":"a87d7944-7b19-4c63-bfd0-cfaeadeb7864"}],"recentChangeFlags":null},{"id":"4062ad7e-b810-4d2a-89ea-fee0c636fe74","uri":"https://apps.apple.com/us/app/asana-mobile/id489969512","name":"Asana iOS app","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"43d77254-416a-4776-9146-95f1ebe26112","sortOrder":0},"sortOrder":0,"tags":[{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"4062ad7e-b810-4d2a-89ea-fee0c636fe74"}],"recentChangeFlags":null},{"id":"364ed3d1-9aaa-4832-830f-f2dcccf697e5","uri":"https://play.google.com/store/apps/details?id=com.asana.app\u0026hl=en","name":"Asana Android app","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"1a356065-b702-4210-9971-f43e20427ee6","sortOrder":0},"sortOrder":0,"tags":[{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"364ed3d1-9aaa-4832-830f-f2dcccf697e5"}],"recentChangeFlags":null},{"id":"e53080f4-4467-401a-84c4-24baef09dbf1","uri":"https://form.asana.com","name":"form.asana.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"00f09a56-d584-4605-91f0-c67664a4251a","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e53080f4-4467-401a-84c4-24baef09dbf1"}],"recentChangeFlags":null},{"id":"7597c735-735a-4bf9-8334-c14bf43656db","uri":null,"name":"*.app.asana.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"31b9167b-d469-48d2-88db-4396d605581c","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7597c735-735a-4bf9-8334-c14bf43656db"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"5e2f8b6a-450e-4314-ac7d-af5e452e50af","p1MaxCents":650000,"p1MinCents":250000,"p2MaxCents":250000,"p2MinCents":100000,"p3MaxCents":100000,"p3MinCents":50000,"p4MaxCents":50000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eThe applications that access *.asana.plus can be found on the \u003ca href=\"https://asana.com/apps?category=made-by-asana\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003efollowing page\u003c/a\u003e. Please note that only the apps made by Asana would be in scope.\u003c/p\u003e","rewardRangeData":{"1":{"min":2500,"max":6500},"2":{"min":1000,"max":2500},"3":{"min":500,"max":1000},"4":{"min":100,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"d39b6ac8-fe59-439a-b636-a69db2c8ba24","name":"Asana Enterprise Technology Scope","targets":[{"id":"68060f72-bb90-4cdf-9a7e-ab87bda99f98","uri":"https://*.asana.biz","name":"*.asana.biz","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f7c0e09c-295c-466e-a1c9-1b718087fd76","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"df79f5e7-3da8-433d-b05f-e68241c40144","uri":"","name":"Subdomain takeover at *asana.biz","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"53b7dfca-9446-4696-87dc-654dbdbf2931","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"cd296f97-f733-4024-b5ae-f540e9fe7cdf","p1MaxCents":300000,"p1MinCents":300000,"p2MaxCents":150000,"p2MinCents":150000,"p3MaxCents":50000,"p3MinCents":50000,"p4MaxCents":25000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eAsana’s Enterprise Technology team welcomes responsible disclosure of impactful security issues. We are particularly interested in the following types of vulnerabilities:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eRemote Code Execution (RCE)\u003c/li\u003e\n\u003cli\u003eServer-Side Request Forgery (SSRF)\u003c/li\u003e\n\u003cli\u003ePath Traversal\u003c/li\u003e\n\u003cli\u003eLocal and Remote File Inclusion (LFI/RFI)\u003c/li\u003e\n\u003cli\u003eCross-Site Scripting (XSS) – excluding self-XSS\u003c/li\u003e\n\u003cli\u003eLeakage of Personally Identifiable Information (PII)\u003c/li\u003e\n\u003cli\u003eSecurity Misconfigurations – with clear security impact\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAdditionally, we are interested in any vulnerabilities that enable threat actors to:\u003cbr\u003e\nRead arbitrary files / Execute system-level commands / Access sensitive or internal information not intended for public disclosure\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eNotes:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eValid subdomain takeover reports are welcome and will be accepted as P4 severity submissions, in line with our prioritization guidelines.\u003c/li\u003e\n\u003cli\u003ePlease make sure to review the Out of Scope section for Enterprise Technology targets before submitting your report to avoid any confusion.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":3000,"max":3000},"2":{"min":1500,"max":1500},"3":{"min":500,"max":500},"4":{"min":250,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"7d8388dc-c649-44be-881e-d5df6640b61f","name":"Out of Scope","targets":[{"id":"a632a421-adb5-47bd-8e90-d60214ddb4de","uri":null,"name":"Other subdomains of asana.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b65b69af-16ad-4b20-9a90-8b83e306bf61","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"c23ca19c-f928-46dd-882e-f690a4aca0f5","uri":null,"name":"Social engineering against Asana Support or Asana Employees","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6da3e2e0-2f6c-46dd-908c-560d5fc7d108","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"46f10486-ccce-42ab-97a8-90ec7caf5f51","uri":"","name":"jira*.integrations.asana.plus","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"517fa082-56a4-4014-ac3d-5b9b8e1a2b50","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"8f5333e3-5cfb-4186-8edc-3bf35d9cbc7d","uri":"","name":"asana.okta.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"44cb7854-957c-486d-935a-b14fb825865d","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"097d4991-ca8d-4646-90b9-f4dacd47a548","uri":"","name":"assets.asana.biz","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"dc619fe1-87a7-4785-be06-230818221af9","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"de2e1f58-208b-4851-9174-53aa4fc0a07f","uri":"","name":"Forms that you do not own","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"734a0a79-32f6-442c-bfcd-f0d676dcb658","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":2,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"f499f4ab-ad05-46e4-9ddc-984be61cf511","code":"asana","state":"in_progress","endsAt":null,"bountyId":"954a0fab-ec91-46f0-8984-1ca7d2c76830","startsAt":"2020-07-16T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/a744/cc17/faf23ed3/2fd06e112ea1f26135f8253031539d11_asana-square.png","logoBackgroundColor":"#242B36","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"ngpt","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2020-07-16T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/asana","changelogs":"/engagements/asana/changelog","submissions":null,"announcements":"/engagements/asana/announcements","hallOfFame":"/engagements/asana/hall_of_fames","crowdstream":"/engagements/asana/crowdstream"},"announcementsCount":11,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/asana/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=asana\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/asana/engagement_subscribers","engagementChangelogsUrl":"/engagements/asana/changelog","publishedAt":"2026-02-03T18:26:16.895Z","engagementChangelogUrl":"/engagements/asana/changelog/ad976c03-b976-410d-bd0a-5d76d56b9477","createUserFeedbacksUrl":"/engagements/asana/feedbacks","engagementCrowdstreamUrl":"/engagements/asana/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}