{"id":"7ecfb9b0-1b37-4a13-b369-b518c45d4d4f","engagementId":"f5b9615f-c545-4ef0-bc70-f380d76c1cdf","data":{"brief":{"id":"5ffcdbf1-fa07-4383-9ada-84ee89a354eb","name":"BrowserStack Inc. Marketplace Managed Bug Bounty Engagement","tagline":"The most comprehensive test platform with AI agents across the testing lifecycle. Open and flexible.","description":"\u003ch2\u003eThis bounty is part of the Atlassian Marketplace Bug Bounty Program\u003c/h2\u003e\n\n\u003cp\u003eBrowserStack Inc.  is committed to security and appreciates the efforts of security researchers. By collaborating through this bug bounty engagement, we aim to strengthen the security of our Atlassian Marketplace applications. Thank you in advance for your contributions!\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eRatings/Rewards:\u003c/strong\u003e\u003cbr\u003e\n\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher, along with the opportunity to appeal and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eRewards will be distributed once for a set of vulnerabilities sharing the same root cause. If multiple endpoints are affected, please group them into a single submission.\u003c/p\u003e\n\n\u003cp\u003eAdditionally, there are shared code bases between the targets listed. We are listing both options so that you have flexibility in testing but we will consider these targets duplicates of each other.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of BrowserStack Inc.  not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but demonstrably belongs to BrowserStack Inc.  you can report it to this program. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cp\u003eBelow is a list of some of the vulnerability classes that we are seeking reports for:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCross Instance Data Leakage/Access (Unauthorized data access between instances)\u003c/li\u003e\n\u003cli\u003eServer-side Remote Code Execution (RCE)\u003c/li\u003e\n\u003cli\u003eServer-Side Request Forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eStored/Reflected Cross-site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eCross-site Request Forgery (CSRF)\u003c/li\u003e\n\u003cli\u003eSQL Injection (SQLi)\u003c/li\u003e\n\u003cli\u003eXML External Entity Attacks (XXE)\u003c/li\u003e\n\u003cli\u003eAccess Control Vulnerabilities (Insecure Direct Object Reference issues, etc)\u003c/li\u003e\n\u003cli\u003ePath/Directory Traversal Issues\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eCredentials:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eResearchers should use the \"bugbounty-test-\u0026lt;bugcrowd-name\u0026gt;.atlassian.net\" namespace\u003c/strong\u003e provided in the instructions below. \u003cstrong\u003e\u003cem\u003ePlease do not create additional instances outside of this namespace for testing.\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003eCreating Your Instance\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eJIRA + Confluence Cloud\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eTo access the instance and start your testing (after you've read and understood the scope and exclusions listed below, of course) you can follow the below steps:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNavigate to the signup page and complete the sign up by email process \u003ca href=\"https://www.atlassian.com/try/cloud/signup?product=confluence.ondemand,jira-software.ondemand,jira-servicedesk.ondemand,jira-core.ondemand\u0026amp;developer=true\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eClick \"Agree\"\u003c/li\u003e\n\u003cli\u003eComplete the form, using the following format: \u003cstrong\u003ebugbounty-test-\u0026lt;bugcrowd-name\u0026gt;\u003c/strong\u003e\nNote that \u0026lt;bugcrowd-name\u0026gt; should be replaced with your own bugcrowd username \u003c/li\u003e\n\u003cli\u003eClick \"Start now\"\u003c/li\u003e\n\u003cli\u003eOnce your instance has been completed that's it - you can test away.\u003c/li\u003e\n\u003cli\u003eProceed to the application's marketplace listing and install the respective application. There is a tab for installation instructions should you need guidance.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eServer and Data Center Sign up pages:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.atlassian.com/software/jira/download\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://www.atlassian.com/software/jira/download\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.atlassian.com/software/jira/download/data-center\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://www.atlassian.com/software/jira/download/data-center\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.atlassian.com/software/confluence/download\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://www.atlassian.com/software/confluence/download\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.atlassian.com/software/confluence/download/data-center\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://www.atlassian.com/software/confluence/download/data-center\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eTo access the instance and start your testing (after you've read and understood the scope and exclusions listed below, of course) you can follow the below steps:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNavigate to the signup page and complete the signup process by email \u003ca href=\"https://www.atlassian.com/software/confluence/download/data-center\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eSelect the release you would like to use and click \"Get Started\"\n-Agree to the terms and conditions and click  \"Submit\"\u003c/li\u003e\n\u003cli\u003eFollow the rest of the installation \u003ca href=\"https://confluence.atlassian.com/doc/installing-confluence-data-center-203603.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003einstructions\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eOnce your instance has been completed that's it - you can test away.\u003c/li\u003e\n\u003cli\u003eProceed to the application's marketplace listing and install the respective application. There is a tab for installation instructions should you need guidance.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 14 days has gone by\u003c/li\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2025, we would consider it in-scope on 01/15/2025\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eBrowserStack’s Commitment\u003c/h2\u003e\n\n\u003cp\u003eTo the best of our ability, we will confirm the existence of the vulnerability and be transparent about the steps taken during the remediation process, including on issues or challenges that may delay resolution.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eLegal Terms\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eIn connection with your participation in this program, you agree to comply with BrowserStack’s Terms of Service, BrowserStack’s Privacy Policy, and all applicable laws and regulations, including any laws or regulations governing privacy or the lawful processing of data.\u003cbr\u003e\nBrowserStack reserves the right to change or modify the terms of this program at any time. You may not participate in this program if you are a resident or individual within a country appearing on any U.S. sanctions lists (such as the lists administered by the US Department of the Treasury’s OFAC).\u003c/p\u003e\n\n\u003cp\u003eBrowserStack does not give permission/authorization (either implied or explicit) to an individual or group of individuals to (1) extract personal information or content of BrowserStack’s users or publicize this information on the open, public-facing internet without user consent or (2) modify or corrupt programs or data belonging to BrowserStack to extract and publicly disclose data belonging to BrowserStack.\u003c/p\u003e\n\n\u003cp\u003eBrowserStack employees (including former employees that separated from BrowserStack within the prior 12 months), contingent workers, contractors, and their personnel, and consultants, as well as their immediate family members and persons living in the same household, are not eligible to receive bounties or rewards of any kind under any BrowserStack programs, whether hosted by BrowserStack or any third party.\u003c/p\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 Vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eClickjacking or issues exploitable only through clickjacking.\u003c/li\u003e\n\u003cli\u003eCSRF on forms available to anonymous users (e.g., contact forms).\u003c/li\u003e\n\u003cli\u003eUsername/email enumeration.\u003c/li\u003e\n\u003cli\u003eCache-Control and Pragma issues.\u003c/li\u003e\n\u003cli\u003eLocal access-required XSS (e.g., User-Agent Header injection), unless demonstrably exploitable through off-path MitM attacks.\u003c/li\u003e\n\u003cli\u003eKnown library vulnerabilities or outdated third-party library reports, unless proven exploitable.\u003c/li\u003e\n\u003cli\u003eSource code disclosure.\u003c/li\u003e\n\u003cli\u003eNon-confidential information disclosure (e.g., issue/project IDs, commit hashes).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cp\u003eWhile reporting vulnerabilities, please consider the attack scenario / exploitability and the security impact of the bug. Use of automated scanners and tools to find vulnerabilities is strictly not allowed. BrowserStack requests that researchers do not perform automated/scripted testing on our infrastructure.\u003c/p\u003e\n\n\u003cp\u003eThe following issues are considered out of scope:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSelf-XSS and XSS without impact\u003c/li\u003e\n\u003cli\u003eUsername / Email Enumeration\u003c/li\u003e\n\u003cli\u003eWeak password policies\u003c/li\u003e\n\u003cli\u003eWeak Captcha / Captcha bypass\u003c/li\u003e\n\u003cli\u003eSession Timeout\u003c/li\u003e\n\u003cli\u003eServices listening on port 80\u003c/li\u003e\n\u003cli\u003eInternal IP address disclosure\u003c/li\u003e\n\u003cli\u003eCookie expiration\u003c/li\u003e\n\u003cli\u003eMissing cookie flags\u003c/li\u003e\n\u003cli\u003eDistributed Denial of Service attacks and Denial of Service attacks\u003c/li\u003e\n\u003cli\u003eResource Exhaustion attacks\u003c/li\u003e\n\u003cli\u003eMail Server Domain Misconfiguration (including email spoofing, missing DMARC, SPF/DKIM, etc.)\u003c/li\u003e\n\u003cli\u003ePresence of autocomplete or save password.\u003c/li\u003e\n\u003cli\u003eBanner grabbing / Version disclosure\u003c/li\u003e\n\u003cli\u003eExploits/Attacks that need MITM or physical access to the victim’s device\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries/packages without a working Proof of Concept\u003c/li\u003e\n\u003cli\u003eClickjacking\u003c/li\u003e\n\u003cli\u003eUnauthenticated/logout/login CSRF\u003c/li\u003e\n\u003cli\u003eCross-site Request Forgery with no or low impact\u003c/li\u003e\n\u003cli\u003eOpen Redirects without demonstrating additional security impact (such as stealing auth tokens)\u003c/li\u003e\n\u003cli\u003eGeneric error messages\u003c/li\u003e\n\u003cli\u003eAttacks that only work against yourself (e.g. host header injection)\u003c/li\u003e\n\u003cli\u003eStrict transport security (HSTP/HSTS) is not enforced\u003c/li\u003e\n\u003cli\u003e0-Day vulnerabilities reported in the last 90 days.\u003c/li\u003e\n\u003cli\u003eCVEs reported in the last 90 Days.\u003c/li\u003e\n\u003cli\u003eSSL/TLS configuration issues, such as:\u003c/li\u003e\n\u003cli\u003ePerfect Forward Secrecy not supported, TLSv1.0 / 1.1\u003c/li\u003e\n\u003cli\u003eInsecure SSL/TLS ciphers (unless you have a working proof of concept)\u003c/li\u003e\n\u003cli\u003eStack traces, directory listings or path disclosures unless sensitive information like source code can be retrieved.\u003c/li\u003e\n\u003cli\u003eWindow.opener issues (“Tab-Nabbing” or other rel=”noopener” bugs)\u003c/li\u003e\n\u003cli\u003eTheoretical sub-domain takeovers with no supporting evidence\u003c/li\u003e\n\u003cli\u003eMissing rate limits\u003c/li\u003e\n\u003cli\u003eBrute Force Attacks\u003c/li\u003e\n\u003cli\u003eHTTPS mixed content scripts.\u003c/li\u003e\n\u003cli\u003eCORS issues without a working PoC\u003c/li\u003e\n\u003cli\u003eOut-of-date software, unless you have a working proof of concept.\u003c/li\u003e\n\u003cli\u003eHTTP Request smuggling without any proven impact\u003c/li\u003e\n\u003cli\u003eArbitrary file upload without proof of the existence of the uploaded file\u003c/li\u003e\n\u003cli\u003eCross-domain referrer leakage where referrer does not contain sensitive information\u003c/li\u003e\n\u003cli\u003eMissing security headers\u003c/li\u003e\n\u003cli\u003eMissing CAA headers\u003c/li\u003e\n\u003cli\u003eClient-side caching issues\u003c/li\u003e\n\u003cli\u003eAll device (emulator/simulator) related vulnerabilities.\u003c/li\u003e\n\u003cli\u003eHTTP method enabled – OPTIONS, PUT,GET,DELETE,INFO\u003c/li\u003e\n\u003cli\u003eSSH Servers and services.\u003c/li\u003e\n\u003cli\u003eBugs that simply cause binary to crash.\u003c/li\u003e\n\u003cli\u003eIssues in user management where impact is limited to owner/admins targeting users in their own organisation(issues where lower privileged users can target higher privileged users are in scope).\u003c/li\u003e\n\u003cli\u003eVolumetric attacks e.g.:\n DoS/DDoS/Network DoS\n Rate limiting\n Email bombing/flooding etc.\u003c/li\u003e\n\u003cli\u003eUpload/download malicious files to the platform\u003c/li\u003e\n\u003cli\u003eBlind XSS must not return any user data that you do not have access to (e.g. Screenshots, cookies that aren't owned by you, etc).\u003c/li\u003e\n\u003cli\u003ePlease use the least invasive test possible (e.g. calling 1x1 image or nonexistent page on your web server, etc).\u003c/li\u003e\n\u003cli\u003eIf injecting on any form that may be publicly visible such as forums, etc. Before injection, please make sure your payload can be removed from the site. If it cannot be easily removed, please check with Bugcrowd Support before performing the testing.\u003c/li\u003e\n\u003cli\u003ePivoting or post-exploitation attacks (i.e. using a vulnerability to find another vulnerability)\u003c/li\u003e\n\u003cli\u003eCustomer cloud instances and data are explicitly out of scope.\u003c/li\u003e\n\u003cli\u003eAutomated scanners\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eYou must ensure that customer data is not affected in any way as a result of your testing. Please ensure you're being non-destructive whilst testing and are only testing on instances that you own.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIn addition to the above, customer instances are not to be accessed in any way (i.e. no customer data is accessed, and customer credentials are not to be used or \"verified\")\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you believe you have found sensitive customer data (e.g., login credentials, API keys, etc) or a way to access customer data (i.e. through a vulnerability) report it, but do not attempt to successfully validate if/that it works.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cem\u003eUse of any automated tools/scanners is strictly prohibited\u003c/em\u003e and will lead to you being removed from the program (trust us, we have those tools too).\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eReports need to be submitted in plain text (associated pictures/videos are fine as long as they're in standard formats). Non-plain text reports (e.g. PDF, DOCX) will be asked to be resubmitted in plain text.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eGrants/awards are at the discretion of BrowserStack Inc.  and we withhold the right to grant, modify or deny grants. But we'll be fair about it.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eTax implications of any payouts are the sole responsibility of the reporter.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo NOT conduct non-technical attacks such as social engineering, phishing or unauthorized access to infrastructure.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo NOT test the physical security of BrowserStack Inc.  offices, employees, equipment, etc.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eThis bounty follows Bugcrowd’s standard disclosure terms.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003ePublic Disclosure\u003c/h2\u003e\n\n\u003cp\u003eBefore disclosing an issue publicly we require that you first request permission from us. BrowserStack Inc.  will process requests for public disclosure on a per-report basis. Requests to publicly disclose an issue that has not yet been fixed for customers will be rejected. Any researcher found publicly disclosing reported vulnerabilities without BrowserStack Inc.  written consent will have any allocated bounty withdrawn and disqualified from the program.\u003c/p\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003eBrowserStack will not initiate a lawsuit or law enforcement investigation against you in response to reporting a vulnerability if you fully comply with this Policy.\u003c/p\u003e\n\n\u003cp\u003ePlease understand that if your security research involves the networks, systems, information, applications, products, or services of another party (which is not us), that third party may determine whether to pursue legal action.\u003cbr\u003e\nWe cannot and do not authorize security research in the name of other entities. If a third party initiates legal action against you and you have complied with this Policy, we will take reasonable steps to make it known that your actions were conducted in compliance with this Policy. You are expected, as always, to comply with all applicable laws and regulations.\u003c/p\u003e\n\n\u003cp\u003eIf you have concerns or are uncertain whether the security research is consistent with this policy, please contact security@browserstack.com before going any further.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"20d6a638-a44d-488a-b296-1ac30df31ee8","name":"In Scope Targets","targets":[{"id":"bf45a1c6-d406-4ed4-888e-768f3f05cb8d","uri":"https://marketplace.atlassian.com/apps/1230699/browserstack-integration-for-jira?hosting=datacenter","name":"https://marketplace.atlassian.com/apps/1230699/browserstack-integration-for-jira?hosting=datacenter","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"84bbe1ba-27cb-450a-ac92-310d6301911c","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"bf45a1c6-d406-4ed4-888e-768f3f05cb8d"},{"id":"69f9dcc7-e598-4efc-be48-7c36a7689651","name":"Atlassian Forge","targetId":"bf45a1c6-d406-4ed4-888e-768f3f05cb8d"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"bf45a1c6-d406-4ed4-888e-768f3f05cb8d"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"bf45a1c6-d406-4ed4-888e-768f3f05cb8d"}],"recentChangeFlags":null},{"id":"40023ab2-907e-4a32-aebb-9827ae773f1c","uri":"https://marketplace.atlassian.com/apps/1230699/browserstack-integration-for-jira?hosting=cloud","name":"https://marketplace.atlassian.com/apps/1230699/browserstack-integration-for-jira?hosting=cloud","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6b19dc70-f2ee-449e-be0a-c21c9faab4cf","sortOrder":1},"sortOrder":1,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"40023ab2-907e-4a32-aebb-9827ae773f1c"},{"id":"69f9dcc7-e598-4efc-be48-7c36a7689651","name":"Atlassian Forge","targetId":"40023ab2-907e-4a32-aebb-9827ae773f1c"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"40023ab2-907e-4a32-aebb-9827ae773f1c"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"40023ab2-907e-4a32-aebb-9827ae773f1c"}],"recentChangeFlags":null},{"id":"4c8f51ea-5335-47f4-8be9-a842285373ae","uri":"https://marketplace.atlassian.com/apps/1230699/browserstack-test-management-webapp-integration-for-jira?hosting=cloud\u0026tab=overview","name":"https://marketplace.atlassian.com/apps/1230699/browserstack-test-management-webapp-integration-for-jira?hosting=cloud\u0026tab=overview","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a689f793-6ab3-4b00-9556-11f53016ac91","sortOrder":2},"sortOrder":2,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"4c8f51ea-5335-47f4-8be9-a842285373ae"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"4c8f51ea-5335-47f4-8be9-a842285373ae"}],"recentChangeFlags":null},{"id":"977f0ad3-3f23-4f43-8aa9-39a4140def44","uri":"https://marketplace.atlassian.com/apps/1741353933/browserstack-test-management-for-jira?hosting=cloud\u0026tab=overview","name":"https://marketplace.atlassian.com/apps/1741353933/browserstack-test-management-for-jira?hosting=cloud\u0026tab=overview","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c371ea26-1a48-4d0a-aafc-4f7bdfd0945c","sortOrder":3},"sortOrder":3,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"977f0ad3-3f23-4f43-8aa9-39a4140def44"},{"id":"69f9dcc7-e598-4efc-be48-7c36a7689651","name":"Atlassian Forge","targetId":"977f0ad3-3f23-4f43-8aa9-39a4140def44"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"977f0ad3-3f23-4f43-8aa9-39a4140def44"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"977f0ad3-3f23-4f43-8aa9-39a4140def44"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"c834570f-26c6-44e1-9bba-5edeaba825fa","p1MaxCents":150000,"p1MinCents":150000,"p2MaxCents":90000,"p2MinCents":90000,"p3MaxCents":30000,"p3MinCents":30000,"p4MaxCents":10000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":1500,"max":1500},"2":{"min":900,"max":900},"3":{"min":300,"max":300},"4":{"min":100,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"f5b9615f-c545-4ef0-bc70-f380d76c1cdf","code":"browserstack-market","state":"in_progress","endsAt":null,"bountyId":"99ccf48a-1c38-45d9-b8a2-b47d5eeba4c6","startsAt":"2025-11-11T12:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/2f45/c873/588b563b/7320f8f7e73a83d231e37c2750c77428_browserstack_logo.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-11-11T12:00:00.159Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/browserstack-market","changelogs":"/engagements/browserstack-market/changelog","submissions":null,"announcements":"/engagements/browserstack-market/announcements","hallOfFame":"/engagements/browserstack-market/hall_of_fames","crowdstream":"/engagements/browserstack-market/crowdstream"},"announcementsCount":4,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/browserstack-market/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=browserstack-market\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/browserstack-market/engagement_subscribers","engagementChangelogsUrl":"/engagements/browserstack-market/changelog","publishedAt":"2026-08-19T23:43:34.549Z","engagementChangelogUrl":"/engagements/browserstack-market/changelog/7ecfb9b0-1b37-4a13-b369-b518c45d4d4f","createUserFeedbacksUrl":"/engagements/browserstack-market/feedbacks","engagementCrowdstreamUrl":"/engagements/browserstack-market/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}