{"id":"49fdfd92-14df-4c3d-bcde-1da5cf628650","engagementId":"2c77bb1d-7e87-426a-b045-c1b5901ac4d2","data":{"brief":{"id":"16f2fe16-7c33-4e4a-b367-1e87f097a973","name":"Council of the Inspectors General on Integrity and Efficiency Vulnerability Disclosure Program","tagline":"Submit your findings to help secure CIGIE!","description":"\u003cp\u003eThe Council of the Inspectors General on Integrity and Efficiency (CIGIE) was statutorily established as an independent entity within the executive branch by the \"The Inspector General Reform Act of 2008,\" P.L. 110-409 to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAddress integrity, economy, and effectiveness issues that transcend individual Government agencies; \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eand\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIncrease the professionalism and effectiveness of personnel by developing policies, standards, and approaches to aid in the establishment of a well-trained and highly skilled workforce in the offices of the Inspectors General.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"2a38890b-c88e-4bc0-8db0-02059f3fafe6","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of {company} not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to CIGIE, you can report it here. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTarget Information\u003c/h2\u003e\n\n\u003cp\u003eThis policy addresses the Cybersecurity and Infrastructure Security Agency (CISA) Binding Operational Directive (BOD) 20-01, Develop and Publish a Vulnerability Disclosure Policy (VDP). BOD 20-01 requires each federal agency to publish a VDP. Publication of agency VDPs will make it easier for users to report vulnerabilities they find in the Federal Government’s internet-accessible systems.\u003c/p\u003e\n\n\u003cp\u003eCIGIE is committed to ensuring the security of the American public by protecting their information. This policy aims to give security researchers clear guidelines for conducting vulnerability discovery activities and convey our requirements in submitting discovered vulnerabilities to us.\u003c/p\u003e\n\n\u003cp\u003eThis policy describes what systems and types of research are covered under this policy, how to send us vulnerability reports, and how long we ask security researchers to wait before disclosing vulnerabilities. \u003c/p\u003e\n\n\u003cp\u003eWe encourage you to contact us to report vulnerabilities in our systems.\u003c/p\u003e\n\n\u003ch2\u003eAuthorization\u003c/h2\u003e\n\n\u003cp\u003eIf you make a good-faith effort to comply with this policy during your security research, we will consider your research to be authorized. We will work with you to quickly understand and resolve the issue, and CIGIE will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities conducted according to this policy, we will make this authorization known.\u003c/p\u003e\n\n\u003ch2\u003eGuidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eOnce you’ve established that a vulnerability exists or encounter any sensitive data (including personally identifiable information, financial information, or proprietary information or trade secrets of any party), \u003cstrong\u003eyou must stop your test, notify us immediately, and not disclose this data or information to anyone else.\u003c/strong\u003e \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAvoid privacy violations, degradation of user experience, damage or disruption to CIGIE production systems, and destruction or manipulation of data;\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eOnly use exploits to the extent necessary to confirm a vulnerability’s presence. Do not use an exploit to compromise or exfiltrate data, establish persistent command-line access, or use the exploit to pivot to other systems.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eView CIGIE data only to the extent necessary to document the presence of a potential vulnerability.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eProvide CIGIE 90 calendar days after you have received our acknowledgement of receipt of your report before you share information about discovered vulnerabilities to the public.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo not submit low-quality reports or false positives.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eTest Methods\u003c/h2\u003e\n\n\u003cp\u003eYou can conduct your security research activities as long as they do not conflict with the following \u003cstrong\u003eunauthorized activities:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNetwork denial of service (DoS or DDoS) tests or other tests that impair access to or damage system(s) or data;\u003c/li\u003e\n\u003cli\u003ePhysical testing of facilities or resources (e.g., office access, open doors, tailgating);\u003c/li\u003e\n\u003cli\u003eAny non-technical vulnerability testing;\u003c/li\u003e\n\u003cli\u003eSocial engineering (e.g., phishing, vishing, pretexting, baiting, and others);\u003c/li\u003e\n\u003cli\u003eTest any system other than the systems outlined in the ‘Scope’ section below;\u003c/li\u003e\n\u003cli\u003eDisclose vulnerability information except as outlined in the ‘Reporting a Vulnerability’ section below;\u003c/li\u003e\n\u003cli\u003eAny unsolicited electronic emails or email-based attacks on CIGIE users;\u003c/li\u003e\n\u003cli\u003eInject malicious software or conduct privilege escalation;\u003c/li\u003e\n\u003cli\u003eTest third-party applications, websites, or services that integrate with or link to or from CIGIE systems;\u003c/li\u003e\n\u003cli\u003eDelete, alter, share, retain, or destroy CIGIE data;\u003c/li\u003e\n\u003cli\u003eUse an exploit to exfiltrate data, establish command-line access, establish a persistent presence on CIGIE systems, or launch attacks against other CIGIE systems.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eScope\u003c/h2\u003e\n\n\u003cp\u003eThis policy applies to the following systems and services:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e*.cigie.gov\u003c/li\u003e\n\u003cli\u003e*.ignet.gov\u003c/li\u003e\n\u003cli\u003e*.oversight.gov\u003c/li\u003e\n\u003cli\u003e*.pandemicoversight.gov\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eAny service not expressly listed above, such as any connected services, are excluded from scope\u003c/strong\u003e and are not authorized for testing. Additionally, vulnerabilities found in systems from our vendors fall outside of this policy’s scope and should be reported directly to the vendor according to their disclosure policy (if any).\u003c/p\u003e\n\n\u003ch2\u003eReporting a Vulnerability\u003c/h2\u003e\n\n\u003cp\u003eInformation submitted under this policy will be used for defensive purposes only – to mitigate or remediate vulnerabilities. If your findings include newly discovered vulnerabilities that affect all users of a product or service and not solely CIGIE, we may share your report with the Cybersecurity and Infrastructure Security Agency, where it will be handled under their \u003ca href=\"https://www.cisa.gov/coordinated-vulnerability-disclosure-process\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ecoordinated vulnerability disclosure process\u003c/a\u003e. We will not share your name or contact information without express permission.\u003c/p\u003e\n\n\u003cp\u003e**We accept vulnerability reports via BugCrowd. By submitting a vulnerability report, you acknowledge that you do not expect a payment, and you expressly waive any future pay claims against the U.S. Government related to your submission.\u003c/p\u003e\n\n\u003ch2\u003eWhat we would like to see from you\u003c/h2\u003e\n\n\u003cp\u003eWe require that your reports comply with the following:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAdhere to all legal terms and conditions outlined in this policy.\u003c/li\u003e\n\u003cli\u003eDescribe the vulnerability, where it was discovered, and the potential impact of exploitation.\u003c/li\u003e\n\u003cli\u003eOffer a detailed description of the steps needed to reproduce the vulnerability (proof of concept scripts or screenshots are helpful).\u003c/li\u003e\n\u003cli\u003eBe in English, if possible.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eWhat you can expect from us\u003c/h2\u003e\n\n\u003cp\u003eWhen you choose to share your contact information with us, we commit to coordinating with you as openly and as quickly as possible.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWithin five business days, we will acknowledge that your report has been received.\u003c/li\u003e\n\u003cli\u003eTo the best of our ability, we will confirm the existence of the vulnerability to you and be as transparent as possible about what steps we are taking during the remediation process, including issues or challenges that may delay resolution.\u003c/li\u003e\n\u003cli\u003eWe will maintain an open dialogue to discuss the reported issue(s).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"b4692956-f064-431f-9301-6ac2aa412c67","name":"In Scope Targets","targets":[{"id":"a9b5e63f-ec9b-4d69-aa5a-ea515e00350f","uri":" ","name":"*.cigie.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5804b843-6d3b-4a72-a63f-f4eda80a2ef0","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"bdf48a7d-0e95-4ad8-b0de-2e3e6f6d0aa9","uri":"","name":"*.ignet.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b7d6c382-d128-4c97-8b50-4451e391bf7e","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"1f88cf18-74b9-4795-a634-37caf3b6dc66","uri":"","name":"*.oversight.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7a52487f-d01e-47e3-806f-9d3f4d7bea9a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"2c77bb1d-7e87-426a-b045-c1b5901ac4d2","code":"cigie-vdp","state":"in_progress","endsAt":null,"bountyId":"b07ad38e-d195-4191-9b4f-577e1ec3755a","startsAt":"2022-09-29T16:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Government","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/9259/413b/b6590274/29dd5fd3cf43a82be82344591b93574b_CIGIE_logo_-_Icon_size.jpg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2022-09-29T16:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/cigie-vdp","changelogs":"/engagements/cigie-vdp/changelog","submissions":null,"announcements":"/engagements/cigie-vdp/announcements","hallOfFame":"/engagements/cigie-vdp/hall_of_fames","crowdstream":"/engagements/cigie-vdp/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/cigie-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=cigie-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/cigie-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/cigie-vdp/changelog","publishedAt":"2023-12-22T20:33:01.834Z","engagementChangelogUrl":"/engagements/cigie-vdp/changelog/49fdfd92-14df-4c3d-bcde-1da5cf628650","createUserFeedbacksUrl":"/engagements/cigie-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/cigie-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}