{"id":"746d0e2a-2a72-4fdc-a230-80e4c81abe8a","engagementId":"c00f5ae3-6940-4e9f-a353-dcd891f16f28","data":{"brief":{"id":"ffec9c9c-a72b-4d00-a9fd-4f6ade7c7342","name":"Cloudinary","tagline":"Cloud image \u0026 video upload, storage, management \u0026 CDN","description":"\u003ch1\u003eIntroduction\u003c/h1\u003e\n\n\u003cp\u003eCloudinary, a SaaS/API provider that streamlines a website's entire image management pipeline, is the market leader in providing a comprehensive cloud-based image and video management platform.\u003cbr\u003e\nUsing Cloudinary you can easily move all your website’s images and other assets to the cloud. Automatically perform smart image resizing, cropping, merging, overlay, watermark, apply effects, rotations and perform format conversions. All this without installing any complex software. Simply put, if you have images in your web or mobile app, let Cloudinary manage them for you.\u003cbr\u003e\nCloudinary offers comprehensive APIs and administration capabilities and is easy to integrate with any web application. To simplify integration further we also have client libraries for Ruby on Rails, Python/Django, PHP, .NET, Node.js and more. In addition, alternative integration methods allow non-developers, bloggers and website administrators to enjoy Cloudinary with nearly zero code changes.\u003cbr\u003e\nWe truly believe that this program plays a key role in protecting our customers and their data. \u003cbr\u003e\nWe appreciate all security submissions and strive to respond expediently.\u003c/p\u003e\n\n\u003cp\u003eWe are particularly interested and will consider extraordinary submissions for:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIssues that result in a full compromise of a Production system (e.g, RCE, obtaining a shell back from our network)\u003c/li\u003e\n\u003cli\u003eBusiness logic bypasses resulting in a significant impact\u003c/li\u003e\n\u003cli\u003eMajor operational failure (excluding Denial of Service related submissions)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003ePlease read carefully below for submission guidelines and targets\u003c/p\u003e","industryTagId":"95db792c-091b-4c81-8d72-b09b1d065f09","targetsOverview":"\u003ch2\u003eOut-of-scope targets\u003c/h2\u003e\n\n\u003cp\u003eTesting is only authorized on the targets listed as In-Scope. Any domain/property of Cloudinary not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you believe you've identified a vulnerability on a system outside the scope, please reach out to support@bugcrowd.com before submitting.\u003c/p\u003e\n\n\u003ch2\u003eDocumentation:\u003c/h2\u003e\n\n\u003cp\u003ePlease check out our full documentation for feature explanation, what's possible, and our API docs here: \u003ca href=\"https://cloudinary.com/documentation\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://cloudinary.com/documentation\u003c/a\u003e\u003c/p\u003e\n\n\u003ch2\u003eRules of Engagement and Submission\u003c/h2\u003e\n\n\u003cp\u003eYou must use your \u003ccode\u003e@bugcrowdninja\u003c/code\u003e email address to set up your Cloudinary account. The main reason for doing so is that in case of need, our team will know you’re from Bugcrowd and have no malicious intentions.\u003cbr\u003e\nFor more info regarding \u003ccode\u003e@bugcrowdninja\u003c/code\u003e email addresses, see \u003ca href=\"https://researcherdocs.bugcrowd.com/v2.0/docs/your-bugcrowdninja-email-address\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eSubmission should include:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eFull description of the vulnerability being reported, including the exploitability and impact\u003c/li\u003e\n\u003cli\u003eManual step-by-step guide\u003c/li\u003e\n\u003cli\u003eAdditional mandatory information to support the triage processes:\n\n\u003cul\u003e\n\u003cli\u003eVideos\u003c/li\u003e\n\u003cli\u003eScreenshots\u003c/li\u003e\n\u003cli\u003eExploit code\u003c/li\u003e\n\u003cli\u003eWeb/API requests and responses\u003c/li\u003e\n\u003cli\u003eEmail address or Cloud name of any test accounts\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eFor RCE submission also include:\n\n\u003cul\u003e\n\u003cli\u003eSource IP address\u003c/li\u003e\n\u003cli\u003eTimestamp, including time zone\u003c/li\u003e\n\u003cli\u003eFull server requests and responses\u003c/li\u003e\n\u003cli\u003eFilenames of any uploaded files, which must include \u003ccode\u003ebugcrowd\u003c/code\u003e and the timestamp\u003c/li\u003e\n\u003cli\u003eCall-back IP and port, if applicable\u003c/li\u003e\n\u003cli\u003eAny data that was accessed, either deliberately or inadvertently\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eProhibited Actions \u0026amp; Testing:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eUse of automated scanners \u003c/li\u003e\n\u003cli\u003eUploading files that allow arbitrary commands (i.e webshells)\u003c/li\u003e\n\u003cli\u003eCreating and maintaining a persistent connection to the server\u003c/li\u003e\n\u003cli\u003eIntentionally viewing any files or data beyond what is needed to prove the vulnerability\u003c/li\u003e\n\u003cli\u003eDo not test UI widgets posting feedback (“Tell us what you think” form) to \u003ccode\u003ehttps://cloudinary.com/console/api/v1/user/send_feedback\u003c/code\u003e\n\u003c/li\u003e\n\u003cli\u003eDo not attack any 3rd-party supporting Cloudinary services\u003c/li\u003e\n\u003cli\u003eDo not perform any testing on our support system or create any support tickets \u003c/li\u003e\n\u003cli\u003eDo not perform any attack that could harm our services (e.g: DDoS/SPAM)\u003c/li\u003e\n\u003cli\u003eDo not access or modify data that does not belong to you\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eEligibility:\u003c/h3\u003e\n\n\u003cp\u003eFor a submission to be considered eligible, it should meet the following requirements: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe submission must be qualified (see requirements above)\u003c/li\u003e\n\u003cli\u003eThe vulnerability root cause is not already known to us\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eIn \u0026amp; Out of scope vulnerabilities:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eIn-Scope focused vulnerabilities:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCross-site scripting (XSS)\u003c/li\u003e\n\u003cli\u003eCross-site request forgery (CSRF)\u003c/li\u003e\n\u003cli\u003eInsecure direct object references (IDOR)\u003c/li\u003e\n\u003cli\u003eInjection Vulnerabilities\u003c/li\u003e\n\u003cli\u003eAuthentication Vulnerabilities\u003c/li\u003e\n\u003cli\u003eServer-side code execution\u003c/li\u003e\n\u003cli\u003ePrivilege escalation\u003c/li\u003e\n\u003cli\u003eSignificant security misconfiguration\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eOut of scope vulnerabilities:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eExternal SSRF - Cloudinary has built-in functionality to fetch remote URLs to read remote files into the system, via fetch URL (http://res.cloudinary.com/demo/image/fetch/\u0026lt;remote url\u0026gt;), via the upload API's URL parameter https://cloudinary.com/documentation/image_upload_api_reference#upload and in other places in the API. This functionality as it's meant to be used will not be considered an SSRF vulnerability when allowing access to external servers, even though it might be used to anonymously scan other web servers for vulnerabilities or open ports other than common web ports. We will accept disclosures that show how this functionality is used to access internal networks or external services having significant security or DOS impact.\u003c/li\u003e\n\u003cli\u003eClickjacking\u003c/li\u003e\n\u003cli\u003eAnything related to Mail Server Domain Misconfiguration (including email spoofing, missing DMARC, SPF/DKIM, etc.)\u003c/li\u003e\n\u003cli\u003eAnything related to EXIF Geolocation data\u003c/li\u003e\n\u003cli\u003eBrute Force attacks on our Login or Forgot Password pages\u003c/li\u003e\n\u003cli\u003eAccount lockout enforcement\u003c/li\u003e\n\u003cli\u003eInternal IP address disclosure\u003c/li\u003e\n\u003cli\u003eUsername / Email Enumeration\u003c/li\u003e\n\u003cli\u003eNo Captcha / Weak Captcha / Captcha Bypass\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers\u003c/li\u003e\n\u003cli\u003eCookie Issues\u003c/li\u003e\n\u003cli\u003eSSL Issues\u003c/li\u003e\n\u003cli\u003eLack of rate limit\u003c/li\u003e\n\u003cli\u003eWeak password policies (length, complexity, etc.)\u003c/li\u003e\n\u003cli\u003eVulnerabilities impacting only old/end-of-life browsers/plugins including: Issues that have had a patch available from the vendor for at least 6 months Issues on software that is no longer maintained (announced as unsupported/end-of-life or no patches issued in at least 6 months)\u003c/li\u003e\n\u003cli\u003eVulnerabilities primarily caused by browser/plugin defects and not representative of defects in the security of Cloudinary’s platform\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without working proof of concept\u003c/li\u003e\n\u003cli\u003eReports of credentials exposed by other data breaches/known credentials lists\u003c/li\u003e\n\u003cli\u003eReports of automated scanners\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf you have a concern about whether a potential submission is in-scope, please first validate that it is demonstrably owned by Cloudinary, and carefully read the \"In \u0026amp; Out of scope vulnerabilities\", and the \"Targets\" sections. If it is still unclear but you believe it should still be considered, please submit via the program, and include a few sentences describing your judgment regarding scope.\u003c/em\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOut of Scope submissions that will follow these guidelines may be considered in-scope submissions (case-by-case basis).\u003c/li\u003e\n\u003cli\u003eOut of Scope submissions without reasoning and submissions that will not follow these guidelines will be marked as “Out Of Scope” with negative points.\u003c/li\u003e\n\u003cli\u003eSubmissions that demonstrate thoughtful consideration for scope but that we ultimately do not act on will receive a \"Not Applicable\" status, rather than \"Out Of Scope\" with negative points.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003cbr\u003e\nAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003cbr\u003e\nExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003cbr\u003e\nExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003cbr\u003e\nLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003cbr\u003e\nYou are expected, as always, to comply with all applicable laws.\u003cbr\u003e\nIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through this program, or inquire via support@bugcrowd.com before going any further.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"d87780e7-44f3-4af5-b903-a2087acc18a3","name":"In Scope Targets","targets":[{"id":"2c5d9787-8ade-4be9-897b-01d3365bc408","uri":"https://cloudinary.com/console","name":"https://cloudinary.com/console","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"16522334-dd10-42bb-a3d8-93705aeb763c","sortOrder":0},"sortOrder":0,"tags":[{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"2c5d9787-8ade-4be9-897b-01d3365bc408"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2c5d9787-8ade-4be9-897b-01d3365bc408"}],"recentChangeFlags":null},{"id":"38ed5e57-cd50-45dc-843a-e01e5df65ba5","uri":"https://api.cloudinary.com","name":"https://api.cloudinary.com","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"29cfc543-51b5-49a6-ae39-2a6a42972156","sortOrder":1},"sortOrder":1,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"38ed5e57-cd50-45dc-843a-e01e5df65ba5"},{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"38ed5e57-cd50-45dc-843a-e01e5df65ba5"},{"id":"6a9fe373-cb50-48a4-8f00-f390acde8447","name":"JSON","targetId":"38ed5e57-cd50-45dc-843a-e01e5df65ba5"},{"id":"cbf0ee58-c41b-4dee-9d08-cefd01f5d7d6","name":"HTTP","targetId":"38ed5e57-cd50-45dc-843a-e01e5df65ba5"}],"recentChangeFlags":null},{"id":"4d10c13a-1514-4ace-9b62-4ef4bb589d6e","uri":"https://res.cloudinary.com","name":"https://res.cloudinary.com","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"91015433-55e0-4d25-aa13-90de898aacb6","sortOrder":2},"sortOrder":2,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"4d10c13a-1514-4ace-9b62-4ef4bb589d6e"},{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"4d10c13a-1514-4ace-9b62-4ef4bb589d6e"},{"id":"6a9fe373-cb50-48a4-8f00-f390acde8447","name":"JSON","targetId":"4d10c13a-1514-4ace-9b62-4ef4bb589d6e"},{"id":"cbf0ee58-c41b-4dee-9d08-cefd01f5d7d6","name":"HTTP","targetId":"4d10c13a-1514-4ace-9b62-4ef4bb589d6e"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"871ba14b-ce40-47e7-819e-f7fea85caab9","p1MaxCents":400000,"p1MinCents":200000,"p2MaxCents":200000,"p2MinCents":50000,"p3MaxCents":50000,"p3MinCents":null,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":700000},"descriptionHtml":null,"rewardRangeData":{"1":{"min":2000,"max":4000},"2":{"min":500,"max":2000},"3":{"min":0,"max":500},"4":{"min":null,"max":null},"5":{"min":null,"max":null},"programMax":7000},"recentChangeFlags":null},{"id":"f659f8b6-041e-4009-a433-8464b6a8db0a","name":"In Scope Tier II","targets":[{"id":"fe7a647e-d851-487a-9072-d1dfb181f703","uri":"https://mediaflows.cloudinary.com/","name":"mediaflows.cloudinary.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"274f36df-e9ee-427d-8288-835f832f23cc","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"fe7a647e-d851-487a-9072-d1dfb181f703"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"fe7a647e-d851-487a-9072-d1dfb181f703"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"fe7a647e-d851-487a-9072-d1dfb181f703"}],"recentChangeFlags":null},{"id":"9327489f-d558-4923-aaef-00918bdd5164","uri":"https://dimensions.cloudinary.com","name":"dimensions.cloudinary.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8ccfa046-5daa-4bc7-8b12-e64f69e6fdb0","sortOrder":1},"sortOrder":1,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"9327489f-d558-4923-aaef-00918bdd5164"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9327489f-d558-4923-aaef-00918bdd5164"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"2de4dc95-8bfa-40f3-8946-4603afffff8f","p1MaxCents":100000,"p1MinCents":50000,"p2MaxCents":50000,"p2MinCents":null,"p3MaxCents":null,"p3MinCents":null,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":500,"max":1000},"2":{"min":0,"max":500},"3":{"min":null,"max":null},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"f4a166de-7399-4e64-9d4b-3b82c58b1f7c","name":"Out of scope","targets":[{"id":"f0464701-dba1-4864-ba4c-39fa68b3c9c1","uri":null,"name":"https://support.cloudinary.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"2bcbcb3b-d85d-409c-bedb-b2a7c19b4f02","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f0464701-dba1-4864-ba4c-39fa68b3c9c1"}],"recentChangeFlags":null},{"id":"ffa36883-a2ef-47b2-bde8-7b1201d0ff93","uri":null,"name":"wiki.cloudinary.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"76e43cee-9cdf-4ce5-927b-32d0a0cbc9e1","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ffa36883-a2ef-47b2-bde8-7b1201d0ff93"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":2,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"c00f5ae3-6940-4e9f-a353-dcd891f16f28","code":"cloudinary","state":"in_progress","endsAt":null,"bountyId":"1f64bb54-c98b-472b-844d-f464764bc964","startsAt":"2018-02-14T20:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Cloud","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/00e9/d2ab/8e6d2e66/f41672f6159050694f2c7b3133015a50_cloudinary_cloud_glyph_blue_png.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2018-02-14T20:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/cloudinary","changelogs":"/engagements/cloudinary/changelog","submissions":null,"announcements":"/engagements/cloudinary/announcements","hallOfFame":"/engagements/cloudinary/hall_of_fames","crowdstream":null},"announcementsCount":24,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/cloudinary/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=cloudinary\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/cloudinary/engagement_subscribers","engagementChangelogsUrl":"/engagements/cloudinary/changelog","publishedAt":"2025-01-27T10:06:11.007Z","engagementChangelogUrl":"/engagements/cloudinary/changelog/746d0e2a-2a72-4fdc-a230-80e4c81abe8a","createUserFeedbacksUrl":"/engagements/cloudinary/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}