{"id":"3491b799-94fd-4a62-8ce0-1d5eaa0e09c6","engagementId":"52fbe65e-cfef-4aea-aab0-be05f0626569","data":{"brief":{"id":"961401d8-0825-4bde-80e0-596b6e7490f4","name":"Auth0 by Okta","tagline":"We provide a universal authentication \u0026 authorization platform for web, mobile, and legacy applications.","description":"\u003cp\u003eWe recognize the crucial role of community researcher involvement and the establishment of a robust foundation in safeguarding our customers and their data. We value every security submission and aim to provide prompt responses.\u003c/p\u003e\n\n\u003cp\u003eAuth0 welcomes you to participate in testing and enhancing the security of our Identity Platform. Your dedication and contributions to strengthening our security are greatly appreciated, and we eagerly anticipate collaborating with the researcher community to develop a rewarding and effective bug bounty program. Best of luck and happy hunting!\u003c/p\u003e","industryTagId":"95db792c-091b-4c81-8d72-b09b1d065f09","targetsOverview":"\u003ch3\u003eAuth0 Bonus\u003c/h3\u003e\n\n\u003cp\u003e\u003cstrong\u003eDate:\u003c/strong\u003e April 9th 12:00 AM PST - May 9th 11:59 PM PST\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eScope:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eAuth0 Brand Customization- Emails\u003c/strong\u003e\n\n\u003cul\u003e\n\u003cli\u003eValid submissions include, but are not limited to, cross-tenant access of email templates, reading or modifying sensitive server-side files via email template customizations, any privilege escalation in viewing and editing email templates, and bypassing the escaping functions of the template language (Liquid) to execute code either on the Auth0 server or against another user. Please note that any file access or code execution exclusively within a testing sandbox would not qualify.\u003c/li\u003e\n\u003cli\u003ePlease reference the documentation for setting up email customization \u003ca href=\"https://auth0.com/docs/customize/email\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://auth0.com/docs/customize/email\u003c/a\u003e and \u003ca href=\"https://auth0.com/docs/api/management/v2/email-templates/post-email-templates\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://auth0.com/docs/api/management/v2/email-templates/post-email-templates\u003c/a\u003e. Email testing can be done via \u003ca href=\"https://auth0.com/docs/customize/email/email-templates/customize-email-templates#test-updated-templates\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://auth0.com/docs/customize/email/email-templates/customize-email-templates#test-updated-templates\u003c/a\u003e. An external SMTP server should be configured to access the email template customization.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAuth0 Enteprise Connections\u003c/strong\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuth0 provides Enterprise connections to authenticate users in an external, federated identity provider (IdP). For the enterprise connections authentication bypass, valid submissions must involve one of the Enterprise connector identity providers (see \u003ca href=\"https://auth0.com/docs/authenticate/identity-providers/enterprise-identity-providers\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://auth0.com/docs/authenticate/identity-providers/enterprise-identity-providers\u003c/a\u003e for more details).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eBonus Multiplier\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eP1: 3x\u003c/li\u003e\n\u003cli\u003eP2: 2x\u003c/li\u003e\n\u003cli\u003eP3: 1.5x\u003c/li\u003e\n\u003cli\u003eP4: 1x (no multiplier)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eNote\u003c/strong\u003e\u003cbr\u003e\nNote that submissions that rely on intentionally insecure implementations that do not follow Auth0 documented instructions and best practices will not be accepted.\u003c/p\u003e\n\n\u003cp\u003eOnly submissions submitted after April 9th, 2026, at 12:00 AM PST, will be eligible for the bonus and multiplier. NO EXCEPTIONS!\u003c/p\u003e\n\n\u003cp\u003ePlease note: All eligible reports will be awarded based on triaged severity and impact. Each submission will be reviewed individually to determine its eligibility for a bonus. Per our standard terms of agreement, all eligibility and bonus determinations are made at the sole discretion of Okta and are not subject to negotiation.\u003c/p\u003e\n\n\u003ch3\u003eAI-generated content\u003c/h3\u003e\n\n\u003cp\u003eWe \u003cstrong\u003edo not\u003c/strong\u003e accept reports that contain \u003cstrong\u003elow-effort\u003c/strong\u003e or \u003cstrong\u003eAI-generated content\u003c/strong\u003e. Submissions must demonstrate original analysis, clear understanding of the issue, and actionable detail. Reports lacking meaningful human input will be rejected. \u003cstrong\u003eRepeat offenders will be removed from the program.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch3\u003eResearcher Environment\u003c/h3\u003e\n\n\u003cp\u003e\u003ca href=\"https://manage.cic-bug-bounty.auth0app.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://manage.cic-bug-bounty.auth0app.com\u003c/a\u003e was created solely for researcher testing. Testing any other Auth0 environment is strictly out of scope.\u003c/p\u003e\n\n\u003ch3\u003eHow to Access Researcher Environment\u003c/h3\u003e\n\n\u003cp\u003eAt the bottom of the program page click on \"Get Credentials\". You will be provided the email address \u0026amp; password to your account.\u003cbr\u003e\nAccess your tenant by navigating to: \u003ca href=\"https://manage.cic-bug-bounty.auth0app.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://manage.cic-bug-bounty.auth0app.com/\u003c/a\u003e\u003c/p\u003e\n\n\u003ch3\u003eTenant Members\u003c/h3\u003e\n\n\u003cp\u003eYou will be assigned 3 sets of credentials giving you access to 3 users and 3 tenants.\u003cbr\u003e\nIf you are utilizing Tenant 1, you can invite User 2 \u0026amp; User 3 to Tenant 1 as Tenant Members and set their permissions. You will use the credentials for User 2 \u0026amp; User 3 to access their own tenants, as well as, Tenant 1.\u003c/p\u003e\n\n\u003ch3\u003eOut-of-scope Submissions\u003c/h3\u003e\n\n\u003cp\u003eWe have created a \u003ca href=\"https://manage.cic-bug-bounty.auth0app.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eresearcher environment\u003c/a\u003e and are providing all researchers a tenant and user which you can retrieve at the bottom of the program page by clicking \"Get Credentials. \u003c/p\u003e\n\n\u003cp\u003eAny submissions on auth0.auth0.com \u0026amp; manage.auth0.com will be immediately marked out of scope.\u003c/p\u003e\n\n\u003ch3\u003eAutomated Scanning Tools, DoS Attempts, etc.\u003c/h3\u003e\n\n\u003cp\u003eAny use of automated scanning tools, DoS attempts, etc. will result in an immediate ban from the program. If you are using Burp Intruder, do not exceed more than 5 requests per second.\u003c/p\u003e\n\n\u003ch3\u003eResearcher Personal Data \u0026amp; Researcher Tenant Deprovisioning\u003c/h3\u003e\n\n\u003cp\u003eDo not use tenants created through the bug bounty program for personal use. Do not populate fields with your personal information. Researcher tenants may be deleted at any time. We reserve all rights to delete inactive tenants, data, or malicious behavior that is deemed disruptive to our infrastructure and/or products in this space.\u003c/p\u003e\n\n\u003ch3\u003eRewards\u003c/h3\u003e\n\n\u003cp\u003eEligible reports will be awarded based on severity, to be determined by Okta/Auth0 in its sole discretion.\u003c/p\u003e\n\n\u003cp\u003eFor payout ranges, refer to the In-Scope targets above.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eKeep in mind that no two bugs are created equal. These payouts define general guidelines. The Okta/Auth0 Product Security team will determine the nature and impact of the bugs to identify the appropriate payouts around these guidelines. Awards are granted entirely at the discretion of Okta/Auth0.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch3\u003eDuplicate Submissions\u003c/h3\u003e\n\n\u003cp\u003eAuth0 has maintained a private bug bounty program since 2019 and any submission that were previously discovered will be labeled as duplicates.\u003c/p\u003e\n\n\u003ch3\u003eSecurity Risk \u0026amp; Impact\u003c/h3\u003e\n\n\u003cp\u003eSubmissions will only be eligible for a bounty if there is a security \u003cstrong\u003erisk\u003c/strong\u003e and/or \u003cstrong\u003eimpact\u003c/strong\u003e.\u003c/p\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eIdentity protocol vulnerabilities\n\n\u003cul\u003e\n\u003cli\u003eOAuth 2.0\u003c/li\u003e\n\u003cli\u003eOpenID Connect\u003c/li\u003e\n\u003cli\u003eSAML\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAuthentication or authorization bypass\u003c/li\u003e\n\u003cli\u003ePII exfiltration\u003c/li\u003e\n\u003cli\u003eCross-tenant escalation of privilege\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eTarget Information:\u003c/h3\u003e\n\n\u003cp\u003eThe main targets are the mobile apps, Authentication and Management APIs, the Management\u003cbr\u003e\ndashboard, the MFA offering, SDKs and some websites under the Auth0 brand. \u003c/p\u003e\n\n\u003cp\u003eHere's an index of our current documentation data:\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eTarget\u003c/th\u003e\n\u003cth\u003eDocumentation\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eAuthentication API\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://auth0.com/docs/api/authentication\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://auth0.com/docs/api/authentication\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eManagement API\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://auth0.com/docs/api/management/v2\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://auth0.com/docs/api/management/v2\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eManagement Dashboard\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://auth0.com/docs/dashboard\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://auth0.com/docs/dashboard\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eLock for Web\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://auth0.com/docs/libraries/lock/v11\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://auth0.com/docs/libraries/lock/v11\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eAuth0 SDK for Web\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://auth0.com/docs/libraries/auth0js/v9\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://auth0.com/docs/libraries/auth0js/v9\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eAuth0 Single Page App SDK\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://auth0.com/docs/libraries/auth0-spa-js\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://auth0.com/docs/libraries/auth0-spa-js\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eExpress Open Connect SDK\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/auth0/express-openid-connect\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/auth0/express-openid-connect\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eAuth0 SDK for React Single Page Applications\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://github.com/auth0/auth0-react\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/auth0/auth0-react\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eMultifactor Authentication Overview\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://auth0.com/multifactor-authentication\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://auth0.com/multifactor-authentication\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eMultifactor Authentication Docs\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://auth0.com/docs/multifactor-authentication\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://auth0.com/docs/multifactor-authentication\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eMultifactor Authentication  Video\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://auth0.com/resources/videos/learn-about-guardian-mfa\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://auth0.com/resources/videos/learn-about-guardian-mfa\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eFGA Documentation\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://docs.fga.dev/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.fga.dev/\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eFGA Swagger Documentation\u003c/td\u003e\n\u003ctd\u003e\u003ca href=\"https://docs.fga.dev/api/service/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.fga.dev/api/service/\u003c/a\u003e\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003cp\u003eHere are download links for our Auth0 Guardian application:\u003c/p\u003e\n\n\u003cp\u003eAuth0 Guardian MFA Android: \u003ca href=\"https://play.google.com/store/apps/details?id=com.auth0.guardian\u0026amp;hl=en_US\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGoogle Play Store\u003c/a\u003e\u003cbr\u003e\nAuth0 Guardian MFA IoS: \u003ca href=\"https://apps.apple.com/us/app/auth0-guardian/id1093447833\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eApple App Store\u003c/a\u003e\u003c/p\u003e\n\n\u003ch3\u003eReporting Criteria\u003c/h3\u003e\n\n\u003cp\u003eAll submissions must be in the following format:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre class=\"highlight plaintext\"\u003e\u003ccode\u003eDescription\n\n\nBusiness Impact (how does this affect Auth0?)\n\n\nWorking proof of concept\n\n\nDiscoverability (how likely is this to be discovered)\n\n\nExploitability (how likely is this to be exploited)\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003ch3\u003eRules of Engagement\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eEmployees and relatives are NOT eligible for a bounty\u003c/li\u003e\n\u003cli\u003eNo DoS - Amazon prohibits this activity and testing cluster not scaled for these attacks\u003c/li\u003e\n\u003cli\u003eDo NOT contact support or helpdesk for bugbounty related concerns - please contact bugcrowd support\u003c/li\u003e\n\u003cli\u003ePublicly-known zero-day vulnerabilities will not be considered for eligibility until more than 30 days have passed since patch availability\u003c/li\u003e\n\u003cli\u003eYou are testing on production systems. As such, please refrain from the use of scanning engines or anything that can affect load on our production servers. In addition, use common sense judgement to not do anything to affect our systems in general.\u003c/li\u003e\n\u003cli\u003eCustomer data must not be affected in any way as a result of your testing.\u003c/li\u003e\n\u003cli\u003eCustomer instances must not be accessed in any way.\u003c/li\u003e\n\u003cli\u003eThe use of any automated tools or scanners is prohibited.\u003c/li\u003e\n\u003cli\u003eDo NOT perform any type of burp scans or scanners.\u003c/li\u003e\n\u003cli\u003eDo not conduct non-technical attacks such as social engineering, phishing or unauthorized access to infrastructure.\u003c/li\u003e\n\u003cli\u003eDo not test the physical security of Auth0 offices, employees, equipment, etc.\u003c/li\u003e\n\u003cli\u003eIf you gain access to servers, do not attempt to pivot. Stop all testing and report.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eOut Of Scope\u003c/h3\u003e\n\n\u003cp\u003eThe following finding types are specifically excluded from the bounty:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eGitHub Actions Vulnerabilities - refer to section below\u003c/li\u003e\n\u003cli\u003eDouble-dipping submissions (refer to double-dipping section below)\u003c/li\u003e\n\u003cli\u003eAbandoned/unclaimed domains, domain squatting, link rot, social media hijacking etc\u003c/li\u003e\n\u003cli\u003eCustomize Login Page XSS\u003c/li\u003e\n\u003cli\u003eRace conditions that allow bypassing limits\u003c/li\u003e\n\u003cli\u003eInvalidating session on password change, reset, etc.\u003c/li\u003e\n\u003cli\u003eIncomplete proof of concepts\u003c/li\u003e\n\u003cli\u003eTheoretical vulnerabilities or issues (refer to theoretical issues section below)\u003c/li\u003e\n\u003cli\u003eHost Header Redirect without user impact\u003c/li\u003e\n\u003cli\u003eHTTP 404 codes/pages or other HTTP non-200 codes/pages.\u003c/li\u003e\n\u003cli\u003eFingerprinting / banner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eDisclosure of known public files or directories, (e.g. robots.txt).\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eCSRF on forms that are available to anonymous users (e.g. login or contact form).\u003c/li\u003e\n\u003cli\u003eLogout / Login Cross-Site Request Forgery (logout CSRF).\u003c/li\u003e\n\u003cli\u003ePresence of application or web browser ‘autocomplete’ or ‘save password’ functionality.\u003c/li\u003e\n\u003cli\u003eLack of Security Speedbump when leaving the site.\u003c/li\u003e\n\u003cli\u003eNo Captcha / Weak Captcha / Captcha Bypass\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force and account lockout not enforced\u003c/li\u003e\n\u003cli\u003eHTTP method enabled\n\n\u003cul\u003e\n\u003cli\u003eOPTIONS, PUT,GET,DELETE,INFO\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eWebServer Type disclosures\u003c/li\u003e\n\u003cli\u003eSocial engineering of our service desk, employees or contractors\u003c/li\u003e\n\u003cli\u003ePhysical attacks against Auth0's offices and data centers\u003c/li\u003e\n\u003cli\u003eRequiring a user's physical device\u003c/li\u003e\n\u003cli\u003eError messages with non-sensitive data\u003c/li\u003e\n\u003cli\u003eNon-application layer Denial of Service or DDoS\u003c/li\u003e\n\u003cli\u003eLack of HTTP Only / SECURE flag for cookies\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration\n\n\u003cul\u003e\n\u003cli\u003evia Login Page error message\u003c/li\u003e\n\u003cli\u003evia Forgot Password error message\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers, specifically (https://www.owasp.org/index.php/List_of_useful_HTTP_headers), e.g.\n\n\u003cul\u003e\n\u003cli\u003eStrict-Transport-Security\u003c/li\u003e\n\u003cli\u003eX-Frame-Options\u003c/li\u003e\n\u003cli\u003eX-XSS-Protection\u003c/li\u003e\n\u003cli\u003eX-Content-Type-Options\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy, X-Content-Security-Policy, X-WebKit-CSP\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy-Report-Only\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSPF / DMARC / DKIM Mail and Domain findings\u003c/li\u003e\n\u003cli\u003eEmail Rate Limiting or Spamming\u003c/li\u003e\n\u003cli\u003eDNSSEC Findings\u003c/li\u003e\n\u003cli\u003eCSV Issues\u003c/li\u003e\n\u003cli\u003eAV Scanning\u003c/li\u003e\n\u003cli\u003eSSL Issues, e.g.\n\n\u003cul\u003e\n\u003cli\u003eSSL Attacks such as BEAST, BREACH, Renegotiation attack\u003c/li\u003e\n\u003cli\u003eSSL Forward secrecy not enabled\u003c/li\u003e\n\u003cli\u003eSSL weak / insecure cipher suites\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eCookie Issues\n\n\u003cul\u003e\n\u003cli\u003eHTTPONLY\u003c/li\u003e\n\u003cli\u003eSECURE\u003c/li\u003e\n\u003cli\u003emultiple cookie setting\u003c/li\u003e\n\u003cli\u003eAnything to do with JSESSIONID\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eService Rate Limiting\u003c/li\u003e\n\u003cli\u003eUser or Org enumeration\u003c/li\u003e\n\u003cli\u003eSecurity Image Issues\u003c/li\u003e\n\u003cli\u003eBusiness Logic Issues\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eSDKs\u003c/h3\u003e\n\n\u003cp\u003eAny submissions pertaining to SDKs must not rely on incorrect or unintended implementations of the SDKs. We will accept submissions that can demonstrate exploitation directly from an application build from our SDKs, but not based on individual function calls that are not directly accessible from an application built with the SDK.\u003c/p\u003e\n\n\u003cp\u003eIn the SDKs, we specify that customers should always validate user input and consider to be untrusted, so we will not accept submissions that rely on improperly validated user input. Researchers should be able to demonstrate security impact when applications and endpoints are built according to documentation.\u003c/p\u003e\n\n\u003ch3\u003eTheoretical Issues\u003c/h3\u003e\n\n\u003cp\u003eAny submissions suggesting that an issue \u003cstrong\u003ecould\u003c/strong\u003e lead to or has the potential to cause impact will be considered \u003cstrong\u003eOUT OF SCOPE\u003c/strong\u003e. You \u003cem\u003e\u003cstrong\u003eMUST\u003c/strong\u003e\u003c/em\u003e provide a complete proof of concept demonstrating the attack detailed in the submission.\u003c/p\u003e\n\n\u003ch3\u003eDouble-dipping\u003c/h3\u003e\n\n\u003cp\u003eResearchers are strictly prohibited from double-dipping by reporting issues they've already submitted in the Auth0 private program. Any intentional attempts to do so will result in a permanent ban from the program.\u003c/p\u003e\n\n\u003ch3\u003eGitHub Actions Vulnerabilities\u003c/h3\u003e\n\n\u003cp\u003eYou may submit issues regarding Github Actions token exfiltration, but it will be marked as a duplicate without a bounty.\u003c/p\u003e\n\n\u003ch3\u003eChaining Bugs\u003c/h3\u003e\n\n\u003cp\u003eChaining of bugs is not frowned upon in any way, we love to see clever exploit chains! However, if you have managed to compromise an Auth0 owned server we do not allow for escalations such as port scanning internal networks, privilege escalation attempts, attempting to pivot to other systems, etc. If you get access this level of access to a server please report it us and we will reward you with an appropriate bounty taking into full consideration the severity of what could be done. Chaining a CSRF vulnerability with a self XSS? Nice! Using AWS access key to dump sensitive info? Not cool.\u003c/p\u003e\n\n\u003ch3\u003eUnsure of a vuln?\u003c/h3\u003e\n\n\u003cp\u003eWe base all payouts on \u003cem\u003erisk\u003c/em\u003e \u003cstrong\u003eAND\u003c/strong\u003e \u003cem\u003eimpact\u003c/em\u003e - when in doubt the question always comes down to risk and impact (aka what can actually be done with the vulnerability and what is the consequence to Auth0). If you can demonstrate why a finding has significant impact, then please submit.\u003cbr\u003e\nAs an example: Let's say you can, as a limited admin, see logs that are not in your user role - What is the impact? If this allows you to compromise something else then please detail the full exploit chain and report. However if the only impact is reading logs.. then there is no need to report it as it would fall under - Business Logic \u003cem\u003eREAD\u003c/em\u003e issues.\u003cbr\u003e\nAnother example: Let's say you can, as a limited admin, see a list of applications but you cannot access them - What is the impact? Are you able to utilize the appID and access contents (such as the secret, jwt, etc) of the application with another endpoint? Report it. However, if you're only able to see the list of applications and the names, there is no need to report it.\u003c/p\u003e\n\n\u003ch3\u003eSimilar Bugs\u003c/h3\u003e\n\n\u003cp\u003eBugs of similar nature or root cause reported by the same person may be combined into one item, thus constituting only a single award.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"f497efbd-5639-4d19-b8a9-e6a8ed945fc2","name":"Tier 1 Targets","targets":[{"id":"441398b6-0bd8-4604-9b86-a101c3805247","uri":"","name":"config.cic-bug-bounty.auth0app.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"598d43fa-f1ef-4c40-845a-64818a6bc54b","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"441398b6-0bd8-4604-9b86-a101c3805247"}],"recentChangeFlags":null},{"id":"2c62a493-9e4a-4595-8eaf-dee4ee6b6d18","uri":"https://manage.cic-bug-bounty.auth0app.com/","name":"manage.cic-bug-bounty.auth0app.com (Management Dashboard)","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e7b0fc3f-2a82-48b0-8c33-beed9dfd6d1a","sortOrder":0},"sortOrder":0,"tags":[{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"2c62a493-9e4a-4595-8eaf-dee4ee6b6d18"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2c62a493-9e4a-4595-8eaf-dee4ee6b6d18"}],"recentChangeFlags":null},{"id":"df03161b-4bc7-4d43-877c-f513b79a4188","uri":"","name":"*.cic-bug-bounty.auth0app.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"117fdd25-dab2-4649-80b5-c0cd4cac0b8f","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"df03161b-4bc7-4d43-877c-f513b79a4188"}],"recentChangeFlags":null},{"id":"e6afe55a-fc2e-43d0-9955-0f9a973a0b40","uri":"https://play.google.com/store/apps/details?id=com.auth0.guardian\u0026hl=en_US\u0026gl=US","name":"Auth0 Guardian Android","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6a168fdd-8893-4823-911a-ad6c4bdacb0a","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"e6afe55a-fc2e-43d0-9955-0f9a973a0b40"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"e6afe55a-fc2e-43d0-9955-0f9a973a0b40"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"e6afe55a-fc2e-43d0-9955-0f9a973a0b40"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"e6afe55a-fc2e-43d0-9955-0f9a973a0b40"}],"recentChangeFlags":null},{"id":"830aa487-b0ad-40fe-9b20-d09105a6e84e","uri":"https://apps.apple.com/us/app/auth0-guardian/id1093447833","name":"Auth0 Guardian IoS","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0560be62-2ad6-4c8b-948f-c1ddf07d70f8","sortOrder":0},"sortOrder":0,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"830aa487-b0ad-40fe-9b20-d09105a6e84e"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"830aa487-b0ad-40fe-9b20-d09105a6e84e"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"830aa487-b0ad-40fe-9b20-d09105a6e84e"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"830aa487-b0ad-40fe-9b20-d09105a6e84e"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"830aa487-b0ad-40fe-9b20-d09105a6e84e"}],"recentChangeFlags":null},{"id":"b7fd752b-3ef7-466a-9567-1e79e65d6230","uri":"https://marketplace.auth0.com","name":"marketplace.auth0.com (Auth0 Marketplace)","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"90e125d2-a271-41ff-9da4-993533be4b66","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b7fd752b-3ef7-466a-9567-1e79e65d6230"},{"id":"cbf0ee58-c41b-4dee-9d08-cefd01f5d7d6","name":"HTTP","targetId":"b7fd752b-3ef7-466a-9567-1e79e65d6230"}],"recentChangeFlags":null},{"id":"7b954e9c-da40-4296-b6c6-41b2583064d0","uri":"","name":"MFA Integrations\t","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"70986923-12ca-46a4-a811-948c27d66493","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"fedcfb30-e0c9-4b5a-adb7-cd8df4ba97c0","uri":"https://dashboard.fga.dev/","name":"https://dashboard.fga.dev/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ca33502c-999f-4eb9-97f3-3290e9dca8ae","sortOrder":0},"sortOrder":0,"tags":[{"id":"70f8fc74-f147-45d5-8f56-9bff2f555bd7","name":".NET","targetId":"fedcfb30-e0c9-4b5a-adb7-cd8df4ba97c0"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"fedcfb30-e0c9-4b5a-adb7-cd8df4ba97c0"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"fedcfb30-e0c9-4b5a-adb7-cd8df4ba97c0"},{"id":"cbf0ee58-c41b-4dee-9d08-cefd01f5d7d6","name":"HTTP","targetId":"fedcfb30-e0c9-4b5a-adb7-cd8df4ba97c0"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"fedcfb30-e0c9-4b5a-adb7-cd8df4ba97c0"}],"recentChangeFlags":null},{"id":"955882e6-9d56-483f-a8ba-b20c401ad5a6","uri":"https://api.us1.fga.dev/","name":"https://api.us1.fga.dev/","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1288b466-f0e5-4873-a329-d394bbacce3b","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"955882e6-9d56-483f-a8ba-b20c401ad5a6"},{"id":"70f8fc74-f147-45d5-8f56-9bff2f555bd7","name":".NET","targetId":"955882e6-9d56-483f-a8ba-b20c401ad5a6"},{"id":"cbf0ee58-c41b-4dee-9d08-cefd01f5d7d6","name":"HTTP","targetId":"955882e6-9d56-483f-a8ba-b20c401ad5a6"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"955882e6-9d56-483f-a8ba-b20c401ad5a6"}],"recentChangeFlags":null},{"id":"6876f98d-d149-41b8-9d39-fb4313efc34c","uri":"https://customers.us1.fga.dev/","name":"https://customers.us1.fga.dev/","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b81e1e79-1d53-4386-b2e3-73ce76e7c576","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"6876f98d-d149-41b8-9d39-fb4313efc34c"},{"id":"70f8fc74-f147-45d5-8f56-9bff2f555bd7","name":".NET","targetId":"6876f98d-d149-41b8-9d39-fb4313efc34c"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"6876f98d-d149-41b8-9d39-fb4313efc34c"},{"id":"cbf0ee58-c41b-4dee-9d08-cefd01f5d7d6","name":"HTTP","targetId":"6876f98d-d149-41b8-9d39-fb4313efc34c"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"6876f98d-d149-41b8-9d39-fb4313efc34c"}],"recentChangeFlags":null},{"id":"5ae4c49d-1de4-4c13-80ce-dd7f5853b1d3","uri":"https://play.fga.dev/","name":"https://play.fga.dev/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"04678f12-7e22-4e94-a83c-8d8b5f6566db","sortOrder":0},"sortOrder":0,"tags":[{"id":"70f8fc74-f147-45d5-8f56-9bff2f555bd7","name":".NET","targetId":"5ae4c49d-1de4-4c13-80ce-dd7f5853b1d3"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"5ae4c49d-1de4-4c13-80ce-dd7f5853b1d3"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"5ae4c49d-1de4-4c13-80ce-dd7f5853b1d3"},{"id":"cbf0ee58-c41b-4dee-9d08-cefd01f5d7d6","name":"HTTP","targetId":"5ae4c49d-1de4-4c13-80ce-dd7f5853b1d3"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"5ae4c49d-1de4-4c13-80ce-dd7f5853b1d3"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"91e46df1-9be9-45bf-95c0-7a2504e7d2c4","p1MaxCents":5000000,"p1MinCents":1000000,"p2MaxCents":1000000,"p2MinCents":400000,"p3MaxCents":400000,"p3MinCents":100000,"p4MaxCents":100000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":10000,"max":50000},"2":{"min":4000,"max":10000},"3":{"min":1000,"max":4000},"4":{"min":100,"max":1000},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"31d439af-174f-4742-a7dc-678595b4b984","name":"SDK Targets","targets":[{"id":"ccfbdd9a-8e5f-441f-9d69-340ba9de14f5","uri":"https://github.com/auth0/auth0.js","name":"Auth0 SDK for Web (Auth0.js)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a3cf15b4-e1aa-480c-8aed-924db84c1ba2","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"a9e4b9f0-02f0-4290-99b1-86b14eaee581","uri":"https://github.com/auth0/lock","name":"Lock for Web (lock)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"19f8cbef-ed93-4ea7-a2cc-f60be37eebf5","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"8e948cb5-ef1b-4058-984b-c0320549a97d","uri":"https://github.com/auth0/auth0-spa-js","name":"Auth0 Single Page App SDK (auth0-spa-js)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ee1ad9fa-2bcc-4d94-99da-932c897f1dbb","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"090fc49f-3d09-48a2-b84d-f4d804265bdf","uri":"https://github.com/auth0/Auth0.Net","name":".NET SDK (Auth0.Net)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ec007201-2ab6-4a90-af9f-3038c96b14dd","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"b9e371a8-2a65-4a5b-91d8-591cb5457d6d","uri":"https://github.com/auth0/nextjs-auth0","name":"Auth0 Next.js SDK (nextjs-auth0)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"cd64087f-9f4a-4071-b46a-8b58336b897a","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null},{"id":"1463d09c-4765-43d1-b614-e723533feeca","uri":"https://github.com/auth0/auth0-java","name":"Auth0 Java SDK (auth0-java)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7b4d88cc-3800-4733-b23b-65470e2af5b5","sortOrder":5},"sortOrder":5,"tags":null,"recentChangeFlags":null},{"id":"08109c6e-65c5-4504-8302-f7418dccb43f","uri":"https://github.com/auth0/react-native-auth0","name":"Auth0 React Native SDK (react-native-auth0)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f6a6f2de-8e29-468b-b328-79e7a214f825","sortOrder":6},"sortOrder":6,"tags":null,"recentChangeFlags":null},{"id":"d7a17ebd-e11b-4112-836d-852f0d008b66","uri":"https://github.com/auth0/auth0-php","name":"Auth0 PHP SDK (auth0-php)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"fe6a8f8d-ef61-4d0c-b735-b3b4463a3ff5","sortOrder":7},"sortOrder":7,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"035e4c69-d065-49d0-84c7-558deead560a","p1MaxCents":1500000,"p1MinCents":500000,"p2MaxCents":500000,"p2MinCents":200000,"p3MaxCents":200000,"p3MinCents":50000,"p4MaxCents":50000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":5000,"max":15000},"2":{"min":2000,"max":5000},"3":{"min":500,"max":2000},"4":{"min":100,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"525a6838-c187-4159-9aac-e9feb18846ed","name":"Tier 2 Targets","targets":[{"id":"fe578ffc-6145-42a8-a14a-97095a584609","uri":"","name":"auth0.com\t","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f461337d-e886-499e-8adc-f45bd9035df5","sortOrder":0},"sortOrder":0,"tags":[{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"fe578ffc-6145-42a8-a14a-97095a584609"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"fe578ffc-6145-42a8-a14a-97095a584609"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"fe578ffc-6145-42a8-a14a-97095a584609"}],"recentChangeFlags":null},{"id":"be7c6722-cad0-42e8-abad-925844334569","uri":"","name":"samltool.io\t","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7573abed-5cbe-4dd6-9782-27839a752e06","sortOrder":0},"sortOrder":0,"tags":[{"id":"9f26f47e-4acd-4d8d-aad2-414b6b367eb0","name":"Handlebars","targetId":"be7c6722-cad0-42e8-abad-925844334569"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"be7c6722-cad0-42e8-abad-925844334569"},{"id":"b7116a08-d333-4fd4-a5b7-d715af3f7d23","name":"YUI","targetId":"be7c6722-cad0-42e8-abad-925844334569"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"be7c6722-cad0-42e8-abad-925844334569"}],"recentChangeFlags":null},{"id":"249edf98-27cb-48e0-9593-1aeed7236402","uri":"","name":"webauthn.me\t","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8b537a52-1ab3-4a53-855c-fb9f63189285","sortOrder":0},"sortOrder":0,"tags":[{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"249edf98-27cb-48e0-9593-1aeed7236402"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"249edf98-27cb-48e0-9593-1aeed7236402"},{"id":"d2e9f7fd-1403-4a01-b5b8-fba5e0f49e37","name":"ExpressJS","targetId":"249edf98-27cb-48e0-9593-1aeed7236402"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"249edf98-27cb-48e0-9593-1aeed7236402"}],"recentChangeFlags":null},{"id":"2bac11cc-8846-40d2-80d9-d2b68e569f5f","uri":"","name":"openidconnect.net\t","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"13d0545d-13b3-435c-90e7-02e68ccc13f4","sortOrder":0},"sortOrder":0,"tags":[{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"2bac11cc-8846-40d2-80d9-d2b68e569f5f"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"2bac11cc-8846-40d2-80d9-d2b68e569f5f"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"2bac11cc-8846-40d2-80d9-d2b68e569f5f"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2bac11cc-8846-40d2-80d9-d2b68e569f5f"}],"recentChangeFlags":null},{"id":"caad988e-2eeb-4acc-9d04-0806b311b54f","uri":"","name":"jwt.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"440706ce-4513-4ff4-9e1e-1ccf7b388da0","sortOrder":0},"sortOrder":0,"tags":[{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"caad988e-2eeb-4acc-9d04-0806b311b54f"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"caad988e-2eeb-4acc-9d04-0806b311b54f"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"caad988e-2eeb-4acc-9d04-0806b311b54f"},{"id":"d2e9f7fd-1403-4a01-b5b8-fba5e0f49e37","name":"ExpressJS","targetId":"caad988e-2eeb-4acc-9d04-0806b311b54f"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"caad988e-2eeb-4acc-9d04-0806b311b54f"}],"recentChangeFlags":null},{"id":"e8b31998-e048-4a64-8fb4-61e33978dfe7","uri":"","name":"auth0.net","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"94c4b53e-fee5-412f-9484-518d9d82e6f7","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e8b31998-e048-4a64-8fb4-61e33978dfe7"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":{"id":"035e4c69-d065-49d0-84c7-558deead560a","p1MaxCents":1500000,"p1MinCents":500000,"p2MaxCents":500000,"p2MinCents":200000,"p3MaxCents":200000,"p3MinCents":50000,"p4MaxCents":50000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":5000,"max":15000},"2":{"min":2000,"max":5000},"3":{"min":500,"max":2000},"4":{"min":100,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"6e73c2cc-4893-4e09-9bc3-3bc2d7f8f680","name":"Out of scope targets","targets":[{"id":"29a6b34f-e718-423c-b382-8e110ac8f7e1","uri":"","name":"auth0.auth0.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5b27122a-246b-4a49-b9b2-6ef8c7f7bb39","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"29a6b34f-e718-423c-b382-8e110ac8f7e1"}],"recentChangeFlags":null},{"id":"4ad72d58-4826-4f11-9307-385ff5de2435","uri":"","name":"manage.auth0.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"be9554a1-beee-462c-a5b6-584ca7f7ad09","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"4ad72d58-4826-4f11-9307-385ff5de2435"}],"recentChangeFlags":null},{"id":"9447acc5-b9b8-4619-85ed-941b0f8e48f0","uri":"","name":"accounts.auth0.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"37a610e1-6ff7-4bcb-808b-375b2d028fc3","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9447acc5-b9b8-4619-85ed-941b0f8e48f0"}],"recentChangeFlags":null},{"id":"5db1f308-6f8a-47a9-aef2-f29c6ae3a0fb","uri":"","name":"webtask.io\t","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"71599c92-4514-4eff-8aa2-8a29eb391973","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"5db1f308-6f8a-47a9-aef2-f29c6ae3a0fb"}],"recentChangeFlags":null},{"id":"d49487cb-6e41-4264-be27-04df2c52aeb4","uri":"","name":"phenix.rocks\t","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f8951294-0498-48e3-90ce-3ed4e2fa1fb0","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d49487cb-6e41-4264-be27-04df2c52aeb4"}],"recentChangeFlags":null},{"id":"fc50da29-535c-4f3f-a5c9-fd63a5eb1050","uri":"","name":"Auth0 Docs (including quickstarts)","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"fab7af3c-eca0-4845-87f6-aa043a8fac34","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"fc50da29-535c-4f3f-a5c9-fd63a5eb1050"}],"recentChangeFlags":null},{"id":"8c384eb6-2bd0-44f9-9c5d-aa30355528b6","uri":"","name":"sharelock.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"463a76fe-4ebb-4568-830d-2e308ca04911","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"8c384eb6-2bd0-44f9-9c5d-aa30355528b6"}],"recentChangeFlags":null},{"id":"8b770d3f-c18e-44d5-8495-5a0c4be75841","uri":"","name":"goextend.io\t","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ff1c04ce-dda3-40bf-afef-e1b1d8f06279","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"8b770d3f-c18e-44d5-8495-5a0c4be75841"}],"recentChangeFlags":null},{"id":"b3f73097-38e9-4743-8762-0bd81e8b764b","uri":"","name":"https://support.auth0.com/tickets/new","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a75959de-9062-4c4b-afb8-cadbf808362b","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"ca2bb054-7965-465b-8742-83d0ce482165","uri":"","name":"support.auth0.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"fe7cefb0-9aa5-4f4a-8423-afb6d030def3","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"9fc27c35-d104-4c91-be8c-875ce40fff6b","uri":"","name":"community.auth0.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8aecf993-6b76-43da-b501-a34c790cbf1d","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"571eaa92-b5c9-48b0-af74-4753657d1499","uri":"https://github.com/auth0/passport-wsfed-saml2","name":"Auth0 passport-ws-fed","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7b4868bd-3ae5-4c7c-aac4-408f863ee17b","sortOrder":11},"sortOrder":11,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":3,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"52fbe65e-cfef-4aea-aab0-be05f0626569","code":"auth0-okta","state":"in_progress","endsAt":null,"bountyId":"08fc2d24-90c9-4573-a17e-fa9dd736c60c","startsAt":"2024-04-29T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Cloud","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/4b60/a5c5/dbf46418/e2f8d4cadc5d43877080a72155590302_auth0_logo.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-04-29T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/auth0-okta","changelogs":"/engagements/auth0-okta/changelog","submissions":null,"announcements":"/engagements/auth0-okta/announcements","hallOfFame":"/engagements/auth0-okta/hall_of_fames","crowdstream":"/engagements/auth0-okta/crowdstream"},"announcementsCount":4,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/auth0-okta/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=auth0-okta\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/auth0-okta/engagement_subscribers","engagementChangelogsUrl":"/engagements/auth0-okta/changelog","publishedAt":"2026-04-08T16:27:36.037Z","engagementChangelogUrl":"/engagements/auth0-okta/changelog/3491b799-94fd-4a62-8ce0-1d5eaa0e09c6","createUserFeedbacksUrl":"/engagements/auth0-okta/feedbacks","engagementCrowdstreamUrl":"/engagements/auth0-okta/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}