{"id":"1015a359-fa2e-44de-9caf-90a0a0e02b96","engagementId":"4c2e3268-6b15-4342-beea-d11bafed71d0","data":{"brief":{"id":"26d5f0f4-4e3c-47ce-aabb-8c59c275ee6c","name":"Chipotle Managed Bug Bounty Engagement","tagline":"Chipotle Mexican Grill, Inc., a global restaurant chain, offers responsibly sourced, classically-cooked food with over 3,250 locations, renowned for its accessibility and sustainable business practices.","description":"\u003cp\u003eChipotle Mexican Grill, Inc. (NYSE: CMG) is cultivating a better world by serving responsibly sourced, classically-cooked, real food with wholesome ingredients without artificial colors, flavors or preservatives. Chipotle has over 3,250 restaurants in the United States, Canada, the United Kingdom, France and Germany and is the only restaurant company of its size that owns and operates all its restaurants in North America and Europe. Chipotle is ranked on the Fortune 500 and is recognized on the 2023 list for Fortune's Most Admired Companies and Time Magazine's Most Influential Companies. With over 110,000 employees passionate about providing a great guest experience, Chipotle is a longtime leader and innovator in the food industry. Chipotle is committed to making its food more accessible to everyone while continuing to be a brand with a demonstrated purpose as it leads the way in digital, technology and sustainable business practices. For more information or to place an order online, visit www.chipotle.com.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect and Chipotle Mexican Grill, Inc. believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch4\u003ePlease note: Only Critical (P1), Severe (P2), Moderate (P3), Low (P4) submissions will be rewarded. P5 findings will be marked as Informational.\u003c/h4\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eWe strive to pay bounty on \"Triage\" and will do so when there is high confidence in the accuracy of the assigned scope and severity. Occasionally, we may need to delay payment until we fully investigate the details of a report.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAll bounty amounts will be at the discretion of the Chipotle Bug Bounty team.\u003c/li\u003e\n\u003cli\u003eBounty-eligible findings with priority higher than P4, that include a unique Nuclei Template to validate the finding will be rewarded a $250 bonus payment.\u003c/li\u003e\n\u003cli\u003eVulnerabilities with existing community templates will not be eligible for the bonus payment.\u003c/li\u003e\n\u003cli\u003eChipotle retains a perpetual right to utilize and distribute any templates submitted as part of a report.\u003c/li\u003e\n\u003cli\u003eReports submitted using methods that violate policy rules will not be eligible for reward.\u003c/li\u003e\n\u003cli\u003eUnderstand that there could be submissions for which we accept the risk, have other compensating controls, or will not address in the manner expected.\u003c/li\u003e\n\u003cli\u003eGenerating fraudulent Chipotle coupons or simply getting free meals, to \"steal money from Chipotle\" is typically not evaluated as a critical issue but may still be eligible for a bounty.\u003c/li\u003e\n\u003cli\u003eYou are more likely to receive a bounty by finding and demonstrating a security impact within the published scope rather than by submitting a bug that's outside of scope and trying to convince us why you believe it’s a security risk for Chipotle.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eLegal\u003c/h2\u003e\n\n\u003cp\u003eChipotle reserves the right to modify terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this site regularly as we routinely update our program terms and eligibility, which are effective upon posting. We reserve the right to cancel this program at any time. Must be 18 or older to be eligible for an award. Chipotle is the program owner and all the information described in this “Program Overview” are “program details.” Together these program details and the terms constitute the “Program Brief” referenced in the SDT. You acknowledge and agree (i) that you are already bound to the terms and conditions stated in Bugcrowd’s Standard Disclosure Terms, which can be found at https://www.bugcrowd.com/resources/essentials/standard-disclosure-terms and (ii) that Chipotle may directly enforce any breach by you of the Standard Disclosure Terms, which are supplemented by the additional terms in this program.\u003c/p\u003e\n\n\u003ch2\u003eProgram Eligibility\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou must agree and adhere to the Program Rules and Legal terms as stated in this policy.\u003c/li\u003e\n\u003cli\u003eYou must be the first to submit a sufficiently reproducible report for an issue to be eligible for a bounty.\u003c/li\u003e\n\u003cli\u003eChipotle employees and vendors are not eligible for participation in this program.\u003c/li\u003e\n\u003cli\u003ePast Chipotle employees are subject to a 90-day exclusion cooldown on your participation in this program. We will not accept submissions from you until 90 days after you've left the company, to minimize conflicts of interest.\u003c/li\u003e\n\u003cli\u003eYou must be available to supply additional information, as needed by our team, to reproduce and triage the issue.\u003c/li\u003e\n\u003cli\u003eZero-day vulnerabilities will not be considered for eligibility until more than 30 days have passed since a fix is published.\u003c/li\u003e\n\u003cli\u003eOut-of-scope vulnerability reports may be addressed as a form of vulnerability disclosure but will generally not be considered reward eligible.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eProgram Rules\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003e\u003cstrong\u003eDo\u003c/strong\u003e\u003c/em\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePerform testing using only accounts that are your own personal/test accounts or an account that you have the explicit permission from the account holder to utilize.\u003c/li\u003e\n\u003cli\u003eExercise caution when testing to avoid negative impact to customers and the services they depend on.\u003c/li\u003e\n\u003cli\u003eStop when unsure. If you think you may cause, or have caused, damage with testing a vulnerability, report your initial finding(s) and request authorization to continue testing.\u003c/li\u003e\n\u003cli\u003eIf you can access or modify personal data of Chipotle customers or other sensitive data, immediately contact Chipotle - do not attempt to conduct post-exploitation work.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eDo NOT\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDo not Brute force credentials or guess credentials to gain access to systems.\u003c/li\u003e\n\u003cli\u003eDo not participate in denial-of-service attacks.\u003c/li\u003e\n\u003cli\u003eDo not upload shells or create a backdoor of any kind.\u003c/li\u003e\n\u003cli\u003eDo not engage in any form of social engineering of Chipotle employees, customers, or vendors.\u003c/li\u003e\n\u003cli\u003eDo not engage or target any Chipotle employee, customer or vendor during your testing.\u003c/li\u003e\n\u003cli\u003eDo not attempt to extract, download, or otherwise exfiltrate data which you believe may have personally identifiable information (PII) other than your own.\u003c/li\u003e\n\u003cli\u003eDo not change passwords of any account that is not yours or that you do not have explicit permission to change. If ever prompted to change a password, stop and report the finding immediately to the Program Owner.\u003c/li\u003e\n\u003cli\u003eDo not publicly disclose vulnerability reports that are not resolved and approved for disclosure by Chipotle.\u003c/li\u003e\n\u003cli\u003eDo not use, share, publish, or disclose information obtained while identifying issues. After submitting you must delete, purge, and/or destroy all copies of information or digital samples.\u003c/li\u003e\n\u003cli\u003eDo not submit reports here to engage us to buy your products or services. Please direct your sales inquiries through proper channels.\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"c85cd17d-3c78-44ca-a00b-40aff928e114","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Chipotle Mexican Grill, Inc. not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Chipotle Mexican Grill, Inc., you can report it to this program. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eAccess\u003c/h3\u003e\n\n\u003cp\u003eAll of the targets are accessible via the public internet and available \u003c/p\u003e\n\n\u003cp\u003eWhen accessing any service hosted by Chipotle Mexican Grill, Inc. please add the following request header. \u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eIdentifier\u003c/th\u003e\n\u003cth\u003eHeader\u003c/th\u003e\n\u003cth\u003eExample\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eUsername\u003c/td\u003e\n\u003ctd\u003eX-Bug-Bounty: Bugcrowd-\u0026lt;Username\u0026gt;\u003c/td\u003e\n\u003ctd\u003eX-Bug-Bounty: Bugcrowd-proresearcher\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eCredentials:\u003c/h3\u003e\n\n\u003cp\u003e\u003cem\u003eAccounts are self signup, please use your Bugcrowdninja email\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eCheckout:\u003c/h3\u003e\n\n\u003cp\u003eChipotle does \u003cstrong\u003eNOT\u003c/strong\u003e support order cancellation currently. \u003c/p\u003e\n\n\u003cp\u003eYou may test the checkout process for the following actions -  \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eRedeeming rewards from points.\u003c/li\u003e\n\u003cli\u003eAdding items to a cart.\u003c/li\u003e\n\u003cli\u003eAdding a card to a wallet.\u003c/li\u003e\n\u003cli\u003eRedeeming promo codes.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eDo not place an order if you are not hungry\u003c/strong\u003e. If you place an order, we will \u003cstrong\u003eNOT\u003c/strong\u003e be able to offer refunds or cancel your order.   \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope Vulnerabilities\u003c/h2\u003e\n\n\u003col\u003e\n\u003cli\u003eIn-store technologies.\u003c/li\u003e\n\u003cli\u003eInternational sites such as chipotle.fr, chipotle.de, chipotle.ca and any others that are not explicitly listed in-scope.\u003c/li\u003e\n\u003cli\u003eIf a subdomain is not part of the main online ordering application, it’s likely out of scope.\n\n\u003cul\u003e\n\u003cli\u003eThird party hosted websites – ir.chipotle.com, facilities.chipotle.com, community.chipotle.com etc. \u003c/li\u003e\n\u003cli\u003eInternal service sites presenting a chipotle.com certificate such as help.chipotle.com\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAny vulnerabilities found in third-party software.\u003c/li\u003e\n\u003cli\u003eAny physical attempts against Chipotle property or data centers.\u003c/li\u003e\n\u003cli\u003eRate limit testing, Denial-of-Service attacks and other volume-based tests are\nout-of-scope for the program.\u003c/li\u003e\n\u003cli\u003eMissing cookie flags on non-sensitive cookies.\u003c/li\u003e\n\u003cli\u003eExposure of public keys (these are designed to be public, please review the type\nof encryption key before reporting it).\u003c/li\u003e\n\u003cli\u003eAny research, data access or testing that violates the law.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ecreate a ticket with Bugcrowd Support\u003c/a\u003e for clarification before proceeding.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"fa293a5f-54cc-4b63-bfa5-38f5c2825bec","name":"In Scope","targets":[{"id":"1f44860f-0c68-4ad6-aea8-4a8f779f51d6","uri":"https://www.chipotle.com","name":" https://www.chipotle.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"df894456-c896-4221-a8d3-77ddc5da0140","sortOrder":0},"sortOrder":0,"tags":[{"id":"187a0132-af2c-45e1-b4af-77ac6117b9dc","name":"Adobe Experience Manager","targetId":"1f44860f-0c68-4ad6-aea8-4a8f779f51d6"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"1f44860f-0c68-4ad6-aea8-4a8f779f51d6"},{"id":"ce8ff3cd-4d54-4404-8321-6351781551a3","name":"Vue.js","targetId":"1f44860f-0c68-4ad6-aea8-4a8f779f51d6"}],"recentChangeFlags":null},{"id":"551a2b65-697e-4b96-b614-63d4dddb4cf3","uri":"https://www.chipotle.co.uk","name":" https://www.chipotle.co.uk","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a83d4817-c0bf-410a-a1fb-92c83cb96136","sortOrder":1},"sortOrder":1,"tags":[{"id":"187a0132-af2c-45e1-b4af-77ac6117b9dc","name":"Adobe Experience Manager","targetId":"551a2b65-697e-4b96-b614-63d4dddb4cf3"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"551a2b65-697e-4b96-b614-63d4dddb4cf3"},{"id":"ce8ff3cd-4d54-4404-8321-6351781551a3","name":"Vue.js","targetId":"551a2b65-697e-4b96-b614-63d4dddb4cf3"}],"recentChangeFlags":null},{"id":"5ad0c60d-f033-483a-aeb4-455b830f4519","uri":"https://catering.chipotle.com","name":"https://catering.chipotle.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e86f9e9c-da60-4b6d-911a-b3ae985780e1","sortOrder":2},"sortOrder":2,"tags":[{"id":"187a0132-af2c-45e1-b4af-77ac6117b9dc","name":"Adobe Experience Manager","targetId":"5ad0c60d-f033-483a-aeb4-455b830f4519"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"5ad0c60d-f033-483a-aeb4-455b830f4519"},{"id":"ce8ff3cd-4d54-4404-8321-6351781551a3","name":"Vue.js","targetId":"5ad0c60d-f033-483a-aeb4-455b830f4519"}],"recentChangeFlags":null},{"id":"0553bbab-0033-4140-b865-5e9e78ced97b","uri":"https://services.chipotle.com","name":"Publicly accessible APIs","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a3dd7bae-1f3c-4755-bc4f-039e1db987d9","sortOrder":3},"sortOrder":3,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"0553bbab-0033-4140-b865-5e9e78ced97b"},{"id":"68da3fae-5355-463e-8442-9a5016b1bda0","name":"ASP.NET","targetId":"0553bbab-0033-4140-b865-5e9e78ced97b"},{"id":"9ffd297c-4781-4777-94cf-ef4e2ddda266","name":"C#","targetId":"0553bbab-0033-4140-b865-5e9e78ced97b"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"0553bbab-0033-4140-b865-5e9e78ced97b"}],"recentChangeFlags":null},{"id":"d3ecb84c-6d3b-460c-913d-e17471de15bf","uri":"https://apps.apple.com/us/app/chipotle-fresh-food/id327228455","name":"Chipotle Mexican Grill Mobile (iOS)","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"36776e26-f2e7-4565-b469-85bbd76b5ef0","sortOrder":4},"sortOrder":4,"tags":[{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"d3ecb84c-6d3b-460c-913d-e17471de15bf"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"d3ecb84c-6d3b-460c-913d-e17471de15bf"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"d3ecb84c-6d3b-460c-913d-e17471de15bf"}],"recentChangeFlags":null},{"id":"1f8160ea-c761-48d7-82af-2e49e77ec8f2","uri":"https://play.google.com/store/search?q=chipotle+mexican+grill\u0026c=apps","name":"Chipotle Mexican Grill Mobile (Android)","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3112fc97-5a54-4cd7-bd86-ec7d894ed518","sortOrder":5},"sortOrder":5,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"1f8160ea-c761-48d7-82af-2e49e77ec8f2"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"1f8160ea-c761-48d7-82af-2e49e77ec8f2"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"1f8160ea-c761-48d7-82af-2e49e77ec8f2"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"48acfae9-ac88-4dac-8e90-f08b748e79f0","p1MaxCents":450000,"p1MinCents":350000,"p2MaxCents":250000,"p2MinCents":150000,"p3MaxCents":75000,"p3MinCents":50000,"p4MaxCents":22500,"p4MinCents":17500,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eIn Scope\u003c/h2\u003e\n\n\u003cp\u003eThe Bug Bounty Program will cover the following technological assets owned and\u003cbr\u003e\noperated by Chipotle:\u003cbr\u003e\nIn-scope\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eOnline ordering applications:\na. www.chipotle.com\nb. www.chipotle.co.uk\nc. catering.chipotle.com\u003c/li\u003e\n\u003cli\u003eAPIs:\na. Publicly accessible APIs: services.chipotle.com\u003c/li\u003e\n\u003cli\u003eMobile Applications\na. iOS and Android versions of our official mobile app \u003c/li\u003e\n\u003c/ol\u003e\n\n\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cp\u003eAll of the below targets are publicly accessible. Accounts can be provisioned where self signup is available. \u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003e Online ordering applications:\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003ea.  \u003ca href=\"https://www.chipotle.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://www.chipotle.com\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003eb.  \u003ca href=\"https://www.chipotle.co.uk\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://www.chipotle.co.uk\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003ec.  \u003ca href=\"https://catering.chipotle.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://catering.chipotle.com\u003c/a\u003e\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003e\u003cp\u003eAPIs:\u003cbr\u003e\na.  Publicly accessible APIs: services.chipotle.com\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMobile Applications\u003cbr\u003e\na.  iOS and Android versions of our official mobile app as indicated below: \u003cbr\u003e\n    - iOS Bundle IDs: \u003cbr\u003e\n          - Chipotle US: com.chipotle.Chipotle\u003cbr\u003e\n          - Chipotle UK: com.chipotle.Chipotle.eu\u003cbr\u003e\n     - Android Bundle IDs: \u003cbr\u003e\n          - Chipotle US: com.chipotle.ordering\u003cbr\u003e\n          - Chipotle UK: com.chipotle.ordering.eu\u003c/p\u003e\u003c/li\u003e\n\u003c/ol\u003e","rewardRangeData":{"1":{"min":3500,"max":4500},"2":{"min":1500,"max":2500},"3":{"min":500,"max":750},"4":{"min":175,"max":225},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"4c2e3268-6b15-4342-beea-d11bafed71d0","code":"chipotle-mbb-og","state":"in_progress","endsAt":null,"bountyId":"aded8ca7-b867-47f6-8630-427a30323024","startsAt":"2024-08-13T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Hospitality","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/959e/89f1/495165f1/e35a1e704bbf51f97070ed738fbb543d_chipotle_mexican_grill_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-08-13T18:00:00.036Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/chipotle-mbb-og","changelogs":"/engagements/chipotle-mbb-og/changelog","submissions":null,"announcements":"/engagements/chipotle-mbb-og/announcements","hallOfFame":"/engagements/chipotle-mbb-og/hall_of_fames","crowdstream":"/engagements/chipotle-mbb-og/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/chipotle-mbb-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=chipotle-mbb-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/chipotle-mbb-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/chipotle-mbb-og/changelog","publishedAt":"2025-08-20T18:01:35.296Z","engagementChangelogUrl":"/engagements/chipotle-mbb-og/changelog/1015a359-fa2e-44de-9caf-90a0a0e02b96","createUserFeedbacksUrl":"/engagements/chipotle-mbb-og/feedbacks","engagementCrowdstreamUrl":"/engagements/chipotle-mbb-og/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}