{"id":"df351887-8b57-4dbd-9468-7f9b30554b69","engagementId":"15c6dca8-40ef-4403-825f-04c549cab817","data":{"brief":{"id":"6fb84795-16c6-400f-b13b-ad29d603f63a","name":"CoinDesk Mobile","tagline":"Help Secure CoinDesk - an award-winning media outlet that covers the cryptocurrency industry","description":"\u003cp\u003eCoinDesk is the most trusted media, events, indices and data company for the global crypto economy. Since 2013, CoinDesk Media has led the story of the future of money and investing, illuminating the transformation in society and culture that comes with it. Our award-winning team of journalists delivers news and unparalleled insights that bring transparency, comprehension and context. CoinDesk Events gathers the global crypto, blockchain and Web3 communities at annual events such as Consensus, the world’s largest and longest-running crypto festival. CoinDesk Indices offers expertise in digital asset indices, data and research to educate and empower investors. \u003c/p\u003e\n\n\u003cp\u003eWe are excited for you to participate as a security researcher to help us identify vulnerabilities in our mobile app. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eSeverity Level\u003c/th\u003e\n\u003cth\u003eCritical\u003c/th\u003e\n\u003cth\u003eHigh\u003c/th\u003e\n\u003cth\u003eMedium\u003c/th\u003e\n\u003cth\u003eLow\u003c/th\u003e\n\u003cth\u003eInformational\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eVRT\u003c/td\u003e\n\u003ctd\u003eP1\u003c/td\u003e\n\u003ctd\u003eP2\u003c/td\u003e\n\u003ctd\u003eP3\u003c/td\u003e\n\u003ctd\u003eP4\u003c/td\u003e\n\u003ctd\u003eP5\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eCVSS v3\u003c/td\u003e\n\u003ctd\u003e10.0-9.0\u003c/td\u003e\n\u003ctd\u003e8.9-7.0\u003c/td\u003e\n\u003ctd\u003e6.9-4.0\u003c/td\u003e\n\u003ctd\u003e\u0026lt;= 3.9 Low Impact\u003c/td\u003e\n\u003ctd\u003e\u0026lt;= 3.9 Informational\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003cp\u003eNote Informational/P5 findings are not awarded monetarily. \u003c/p\u003e\n\n\u003cp\u003eCoinDesk reserves the right to make any final determination of rating levels for any reported vulnerability.\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of CoinDesk not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to CoinDesk, you can report it to security.incident@bullish.com. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cp\u003eAssessment should address the OWASP Mobile Top 10: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eM1: Improper Credential Usage\u003c/li\u003e\n\u003cli\u003eM2: Inadequate Supply Chain Security\u003c/li\u003e\n\u003cli\u003eM3: Insecure Authentication/Authorization\u003c/li\u003e\n\u003cli\u003eM4: Insufficient Input/Output Validation\u003c/li\u003e\n\u003cli\u003eM5: Insecure Communication\u003c/li\u003e\n\u003cli\u003eM6: Inadequate Privacy Controls\u003c/li\u003e\n\u003cli\u003eM7: Insufficient Binary Protections\u003c/li\u003e\n\u003cli\u003eM8: Security Misconfiguration\u003c/li\u003e\n\u003cli\u003eM9: Insecure Data Storage\u003c/li\u003e\n\u003cli\u003eM10: Insufficient Cryptography\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eCredentials\u003c/h3\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e You may register for accounts \u003ca href=\"https://www.coindesk.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eNOTE\u003c/strong\u003e - Although not required, signing up will unlock additional features. \u003c/p\u003e\n\n\u003ch3\u003eAccess/Traffic Identification\u003c/h3\u003e\n\n\u003cp\u003ePlease add the following header to your HTTP traffic to prevent interruptions and verify non-malicious behavior:\u003cbr\u003e\n\u003ccode\u003eX-Bug-Bounty:\u0026lt;bugcrowdusername\u0026gt;\u003c/code\u003e\u003c/p\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\n\n\u003cul\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting\u003c/li\u003e\n\u003cli\u003eEmail bombing/flooding\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSocial Engineering\n\n\u003cul\u003e\n\u003cli\u003eFor example, attempts to steal cookies, fake login pages to collect credentials.\u003c/li\u003e\n\u003cli\u003ePhishing.\u003c/li\u003e\n\u003cli\u003ePhysical attacks against Facilities / Property.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eCredential Stuffing / Password Spraying.\u003c/li\u003e\n\u003cli\u003eOpen Redirects.\u003c/li\u003e\n\u003cli\u003eAny type of brute force attacks.\u003c/li\u003e\n\u003cli\u003eClickjacking\u003c/li\u003e\n\u003cli\u003eSubmissions related to past or present data dumps or leaked credentials.\u003c/li\u003e\n\u003cli\u003eEngaging in the trade of stolen/breached user credentials or use leaked credentials dumps in the testing.\u003c/li\u003e\n\u003cli\u003eModifying data residing in an account that does not belong to you.\u003c/li\u003e\n\u003cli\u003eAccessing or downloading data beyond the minimum required to demonstrate a vulnerability.\u003c/li\u003e\n\u003cli\u003eMaking any changes to the system configurations, files, or data.\u003c/li\u003e\n\u003cli\u003eIntroducing a backdoor in any system.\u003c/li\u003e\n\u003cli\u003eAttacking/interacting with our end users in any way.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 14 days has gone by\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2025, we would consider it in-scope on 01/15/2025\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAnything specific to the mobile app is in scope\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eLeaked Credentials\u003c/h2\u003e\n\n\u003cp\u003eIf you happen to identify vulnerabilities involving data that has been exposed or leaked such as dark web forums or leaked credential sites. You can report it to this engagement. However, be aware that it is only eligible for points-based compensation. This policy helps maintain the highest standard of operational confidentiality, integrity, and compliance.\u003c/p\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"418fb5e8-0043-46c0-95d7-8bdfa6953208","name":"In Scope","targets":[{"id":"249f320a-852d-4084-896a-1a9e00cba028","uri":"https://apps.apple.com/us/app/coindesk-crypto-bitcoin-news/id6502816903","name":"iOS app - https://apps.apple.com/us/app/coindesk-crypto-bitcoin-news/id6502816903","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1a3b6325-793b-45da-8236-10dbf6441082","sortOrder":0},"sortOrder":0,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"249f320a-852d-4084-896a-1a9e00cba028"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"249f320a-852d-4084-896a-1a9e00cba028"}],"recentChangeFlags":null},{"id":"7c21281e-26b6-43cd-acc1-e7ce8f580402","uri":"https://play.google.com/store/apps/details?id=com.coindesk.mobile","name":"Android app - https://play.google.com/store/apps/details?id=com.coindesk.mobile","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"589027eb-865f-4c88-a31a-c3581285dc7c","sortOrder":1},"sortOrder":1,"tags":[{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"7c21281e-26b6-43cd-acc1-e7ce8f580402"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"7c21281e-26b6-43cd-acc1-e7ce8f580402"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"8eaa04c8-3571-425e-971d-af20ce5e1567","p1MaxCents":750000,"p1MinCents":350000,"p2MaxCents":350000,"p2MinCents":150000,"p3MaxCents":150000,"p3MinCents":25000,"p4MaxCents":50000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eTargets are the dedicated mobile applications for the CoinDesk.com platform. Vulnerabilities found on the web app can be reported to the \u003ca href=\"https://bugcrowd.com/engagements/coindesk-mbb-og\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCoinDesk.com program.\u003c/a\u003e\u003c/p\u003e","rewardRangeData":{"1":{"min":3500,"max":7500},"2":{"min":1500,"max":3500},"3":{"min":250,"max":1500},"4":{"min":250,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"15c6dca8-40ef-4403-825f-04c549cab817","code":"coindesk-mobile-mbb-og","state":"in_progress","endsAt":null,"bountyId":"0d06e1fa-b0c3-4272-a4c9-afeaa2548950","startsAt":"2025-02-25T14:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/e17e/ae4b/4e04d870/a6fc936fd1997f3d47d9e86a00982f28_Coindesk.jpg","logoBackgroundColor":"#000000","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-02-25T14:00:00.039Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/coindesk-mobile-mbb-og","changelogs":"/engagements/coindesk-mobile-mbb-og/changelog","submissions":null,"announcements":"/engagements/coindesk-mobile-mbb-og/announcements","hallOfFame":"/engagements/coindesk-mobile-mbb-og/hall_of_fames","crowdstream":"/engagements/coindesk-mobile-mbb-og/crowdstream"},"announcementsCount":2,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/coindesk-mobile-mbb-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=coindesk-mobile-mbb-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/coindesk-mobile-mbb-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/coindesk-mobile-mbb-og/changelog","publishedAt":"2025-03-26T13:35:59.703Z","engagementChangelogUrl":"/engagements/coindesk-mobile-mbb-og/changelog/df351887-8b57-4dbd-9468-7f9b30554b69","createUserFeedbacksUrl":"/engagements/coindesk-mobile-mbb-og/feedbacks","engagementCrowdstreamUrl":"/engagements/coindesk-mobile-mbb-og/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}