{"id":"d910ea72-d174-432c-ad2f-11df1a3b729a","engagementId":"aa0555a2-8469-4672-9589-35ba734149db","data":{"brief":{"id":"00932b7f-0bad-433f-8309-ff534a30a25a","name":"eazyBI","tagline":"eazyBI Bug Bounty Program ","description":"\u003cp\u003e\u003cem\u003eThis bounty is part of the Atlassian Marketplace Bounty Program\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eAnalyze and visualize your Jira and Confluence data with just a few clicks.\u003c/p\u003e\n\n\u003ch4\u003eGet Started\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eDo not access, impact, destroy or otherwise negatively impact eazyBI SIA or Atlassian customers, or customer data in any way.\u003c/li\u003e\n\u003cli\u003eEnsure that you use your \u003cem\u003e@bugcrowdninja.com\u003c/em\u003e email address.\u003c/li\u003e\n\u003cli\u003eEnsure you understand the targets, scopes, exclusions, and rules below.\n​\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eQuick Links\u003c/h4\u003e\n\n\u003cp\u003eYou can follow the links here to the targets of the eazyBI program:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://marketplace.atlassian.com/apps/1211051/eazybi-reports-and-charts-for-jira?hosting=cloud\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eeazyBI Reports and Charts for Jira\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://marketplace.atlassian.com/apps/1219504/eazybi-reports-and-charts-for-confluence?hosting=cloud\u0026amp;tab=overview\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eeazyBI Reports and Charts for Confluence\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.eazybi.com/eazybi\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eeazyBI Documentation\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIMPORTANT. The links to targets (except the Documentation) are the location where you can access the eazyBI app from the Atlassian Marketplace. Please, refrain from affecting the listing of the eazyBI app on the Marketplace (e.g. by posting reviews) as it is not in the scope of this program.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cp\u003eWe're more interested in traditional web application vulnerabilities. Below is a list of some of the vulnerability classes that we are seeking reports for:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eServer-side Remote Code Execution (RCE)\u003c/li\u003e\n\u003cli\u003eServer-Side Request Forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eStored/Reflected Cross-site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eCross-site Request Forgery (CSRF)\u003c/li\u003e\n\u003cli\u003eSQL Injection (SQLi)\u003c/li\u003e\n\u003cli\u003eHTML injection\u003c/li\u003e\n\u003cli\u003eAccess Control Vulnerabilities (Insecure Direct Object Reference issues, etc)\u003c/li\u003e\n\u003cli\u003ePath/Directory Traversal Issues\n​\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eEnsure you review the out of scope and exclusions list for further details.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003ePlease ensure you're being non-destructive whilst testing and are only testing using accounts and instances created via the instructions under \"Creating your instance\". Any testing/spamming live support portals or Marketplace sites will disqualify you and you will be banned from Atlassian programs.\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal and make a case for a higher priority. Please see below for deviations.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eNote: eazyBI uses \u003ca href=\"https://www.atlassian.com/trust/security/security-severity-levels\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCVSS\u003c/a\u003e to consistently score security vulnerabilities. Where discrepancies between the VRT and CVSS score exist, eazyBI will defer to the CVSS score to determine the priority.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003ch3\u003eRules, Exclusions, and Scopes \u003c/h3\u003e\n\n\u003ch2\u003eCreating Your Instance\u003c/h2\u003e\n\n\u003cp\u003eTo access the instance and start your testing (after you've read and understood the scope and exclusions listed below, of course) you can follow the below steps:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCreate your instance of Jira and Confluence Cloud according to instructions from the Atlassian Program brief.\u003c/li\u003e\n\u003cli\u003eInstall the eazyBI app for Jira Cloud or app for Confluence Cloud from the Atlassian Marketplace.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cp\u003eAnything not declared as a target or in scope above should be considered out of scope for the purposes of this bug bounty. However to help avoid grey areas, below are examples of what is considered out of scope.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eBlind XSS must not return any user data that you do not have access to (e.g. Screen shots, cookies that aren't owned by you, etc); when testing for blind XSS, please use the least invasive test possible (e.g. calling 1x1 image or nonexistent page on your webserver, etc).\u003c/li\u003e\n\u003cli\u003eWhen testing, please exercise caution if injecting on any form that may be publicly visible - such as forums, etc. Before injection, please make sure your payload can be removed from the site. If it cannot be easily removed, please check with support@bugcrowd before performing the testing. \u003c/li\u003e\n\u003cli\u003eNo pivoting or post exploitation attacks (i.e. using a vulnerability to find another vulnerability) are allowed on this program. DO NOT under any circumstance leverage a finding to identify further issues.\u003c/li\u003e\n\u003cli\u003eCustomer cloud instances and data are explicitly out of scope.\u003c/li\u003e\n\u003cli\u003eAny repository that you are not an owner of - do not impact eazyBI, or Atlassian customers in any way.\u003c/li\u003e\n\u003cli\u003eOnly the latest version of our products are eligible for a reward.\u003c/li\u003e\n\u003cli\u003eAny internal or development services.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eThe following finding types are specifically excluded from the bounty\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe use of Automated scanners is strictly prohibited (we have these tools too - don't even think about using them).\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g. Stack Traces, application or server errors).\u003c/li\u003e\n\u003cli\u003eFingerprinting / banner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eLogout Cross-Site Request Forgery (logout CSRF).\u003c/li\u003e\n\u003cli\u003eContent Spoofing.\u003c/li\u003e\n\u003cli\u003ePresence of application or web browser ‘autocomplete’ or ‘save password’ functionality.\u003c/li\u003e\n\u003cli\u003eLack of Secure/HTTPOnly flags on non-sensitive Cookies.\u003c/li\u003e\n\u003cli\u003eLack of Security Speedbump when leaving the site.\u003c/li\u003e\n\u003cli\u003eWeak Captcha / Captcha Bypass.\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force and account lockout not enforced.\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration.\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers, specifically (\u003ca href=\"https://owasp.org/www-project-secure-headers/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://owasp.org/www-project-secure-headers/\u003c/a\u003e), e.g.\n\n\u003cul\u003e\n\u003cli\u003eStrict-Transport-Security.\u003c/li\u003e\n\u003cli\u003eX-Frame-Options.\u003c/li\u003e\n\u003cli\u003eX-XSS-Protection.\u003c/li\u003e\n\u003cli\u003eX-Content-Type-Options.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy, X-Content-Security-Policy, X-WebKit-CSP.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy-Report-Only.\u003c/li\u003e\n\u003cli\u003eCache-Control and Pragma\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eHTTP/DNS cache poisoning.\u003c/li\u003e\n\u003cli\u003eSSL/TLS Issues, e.g.\n\n\u003cul\u003e\n\u003cli\u003eSSL Attacks such as BEAST, BREACH, Renegotiation attack.\u003c/li\u003e\n\u003cli\u003eSSL Forward secrecy not enabled.\u003c/li\u003e\n\u003cli\u003eSSL weak/insecure cipher suites.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSelf-XSS reports will not be accepted.\n\n\u003cul\u003e\n\u003cli\u003eSimilarly, any XSS where local access is required (i.e. User-Agent Header injection) will not be accepted. The only exception will be if you can show a working off-path MiTM attack that will allow for the XSS to trigger.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerabilities that are limited to unsupported browsers will not be accepted (i.e. \"this exploit only works in IE6/IE7\"). A list of supported browsers can be found \u003ca href=\"https://support.atlassian.com/atlassian-account/docs/supported-browsers-for-atlassian-cloud-products/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eKnown vulnerabilities in used libraries, or the reports that an Atlassian product uses an outdated third party library (e.g. jQuery, Apache HttpComponents etc) unless you can prove exploitability.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect SPF records of any kind.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect DMARC records of any kind.\u003c/li\u003e\n\u003cli\u003eSource code disclosure vulnerabilities.\u003c/li\u003e\n\u003cli\u003eInformation disclosure of non-confidential information (e. g. issue id, project id, commit hashes).\u003c/li\u003e\n\u003cli\u003eThe ability to upload/download viruses or malicious files to the platform.\u003c/li\u003e\n\u003cli\u003eEmail bombing/Flooding/rate limiting.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003ePlease, be aware that you follow the rules for testing specified in the Atlassian program.\u003c/li\u003e\n\u003cli\u003eWe award bounties at the time of the fix, and we will always ask for the validation of the fix before awarding bounties.\u003c/li\u003e\n\u003cli\u003eThe fix-time might depend on the criticality of the reported vulnerability and there is no need for regular reminders and checks about the progress.\u003c/li\u003e\n\u003cli\u003eYou must be the first person to report the issue to us. We will review duplicate bugs to see if they provide additional information, but otherwise we will only reward the first reporter.\u003c/li\u003e\n\u003cli\u003eBoth of our apps (for Jira and Confluence) share part of a common code base; identical vulnerabilities in both apps might be reported, which may be treated as duplicates.\u003c/li\u003e\n\u003cli\u003eGrants/awards are at the discretion of eazyBI and we withhold the right to grant, modify or deny grants. But we'll be fair about it. We always evaluate the overall risk level of the vulnerability reported and the amount of the bounty will depend on the potential impact of the vulnerability.\u003c/li\u003e\n\u003cli\u003eYou must ensure that customer data is not affected in any way as a result of your testing. Please ensure you're being non-destructive whilst testing and are only testing on instances that you own.\u003c/li\u003e\n\u003cli\u003eIn addition to above, customer instances are not to be accessed in any way (i.e. no customer data is accessed, customer credentials are not to be used or \"verified\").\n\n\u003cul\u003e\n\u003cli\u003eIf you believe you have found sensitive customer data (e.g., login credentials, API keys etc) or a way to access customer data (i.e. through a vulnerability) report it, but do not attempt to successfully validate if/that it works.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cem\u003eUse of any automated tools/scanners is strictly prohibited\u003c/em\u003e and will lead to you being removed from the program (trust us, we have those tools too).\u003c/li\u003e\n\u003cli\u003eReports need to be submitted in plain text (associated pictures/videos are fine as long as they're in standard formats). Non-plain text reports (e.g. PDF, DOCX) will be asked to be resubmitted in plain text.\u003c/li\u003e\n\u003cli\u003eTax implications of any payouts are the sole responsibility of the reporter.\u003c/li\u003e\n\u003cli\u003eDo NOT conduct non-technical attacks such as social engineering, phishing or unauthorized access to infrastructure.\u003c/li\u003e\n\u003cli\u003eDo NOT test the physical security of eazyBI offices, employees, equipment, etc.\u003c/li\u003e\n\u003cli\u003eThis bounty follows Bugcrowd’s standard disclosure terms.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003ePublic Disclosure\u003c/h3\u003e\n\n\u003cp\u003eBefore disclosing an issue publicly we require that you first request permission from us. eazyBI will process requests for public disclosure on a per report basis. Requests to publicly disclose an issue that has not yet been fixed for customers will be rejected. Any researcher found publicly disclosing reported vulnerabilities without eazyBI’s written consent will have any allocated bounty withdrawn and disqualified from the program.\u003c/p\u003e\n\n\u003ch3\u003eSafe Harbor\u003c/h3\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\nYou are expected, as always, to comply with all applicable laws.\nIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further.\u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"65ca3ca6-4b5b-43bd-aaff-de574a465139","name":"In Scope Targets","targets":[{"id":"06321985-9d31-4c18-90e1-1b8fd004653b","uri":"https://marketplace.atlassian.com/apps/1211051/eazybi-reports-and-charts-for-jira?hosting=cloud","name":"https://marketplace.atlassian.com/apps/1211051/eazybi-reports-and-charts-for-jira?hosting=cloud","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"8100d070-e6c2-4830-b4c9-6db4eb2f0050","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"06321985-9d31-4c18-90e1-1b8fd004653b"},{"id":"4592d652-bb2d-4ab9-8720-08fe80de0dc4","name":"Backbone","targetId":"06321985-9d31-4c18-90e1-1b8fd004653b"},{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"06321985-9d31-4c18-90e1-1b8fd004653b"},{"id":"866992e9-3297-4b3d-99e3-d74493198f2c","name":"Google Cloud","targetId":"06321985-9d31-4c18-90e1-1b8fd004653b"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"06321985-9d31-4c18-90e1-1b8fd004653b"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"06321985-9d31-4c18-90e1-1b8fd004653b"},{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"06321985-9d31-4c18-90e1-1b8fd004653b"}],"recentChangeFlags":null},{"id":"e8dc9a55-fd2a-4d95-a4f5-e5fa6d96b85e","uri":"https://marketplace.atlassian.com/apps/1211051/eazybi-reports-and-charts-for-jira?hosting=datacenter","name":"https://marketplace.atlassian.com/apps/1211051/eazybi-reports-and-charts-for-jira?hosting=datacenter","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"15b9f121-084b-4822-828b-47255cf9be24","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"e8dc9a55-fd2a-4d95-a4f5-e5fa6d96b85e"},{"id":"4592d652-bb2d-4ab9-8720-08fe80de0dc4","name":"Backbone","targetId":"e8dc9a55-fd2a-4d95-a4f5-e5fa6d96b85e"},{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"e8dc9a55-fd2a-4d95-a4f5-e5fa6d96b85e"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"e8dc9a55-fd2a-4d95-a4f5-e5fa6d96b85e"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e8dc9a55-fd2a-4d95-a4f5-e5fa6d96b85e"},{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"e8dc9a55-fd2a-4d95-a4f5-e5fa6d96b85e"}],"recentChangeFlags":null},{"id":"b2eff8a6-7f66-4fe6-b893-e2a37707b130","uri":"https://marketplace.atlassian.com/apps/1219504/eazybi-reports-and-charts-for-confluence?hosting=cloud","name":"https://marketplace.atlassian.com/apps/1219504/eazybi-reports-and-charts-for-confluence?hosting=cloud","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"2ba30212-c8cb-465d-a76d-7c26deb8b782","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"b2eff8a6-7f66-4fe6-b893-e2a37707b130"},{"id":"4592d652-bb2d-4ab9-8720-08fe80de0dc4","name":"Backbone","targetId":"b2eff8a6-7f66-4fe6-b893-e2a37707b130"},{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"b2eff8a6-7f66-4fe6-b893-e2a37707b130"},{"id":"866992e9-3297-4b3d-99e3-d74493198f2c","name":"Google Cloud","targetId":"b2eff8a6-7f66-4fe6-b893-e2a37707b130"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"b2eff8a6-7f66-4fe6-b893-e2a37707b130"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b2eff8a6-7f66-4fe6-b893-e2a37707b130"},{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"b2eff8a6-7f66-4fe6-b893-e2a37707b130"}],"recentChangeFlags":null},{"id":"9b16bc2f-fc5e-4886-9781-6db87bd486b0","uri":"https://marketplace.atlassian.com/apps/1219504/eazybi-reports-and-charts-for-confluence?hosting=datacenter","name":"https://marketplace.atlassian.com/apps/1219504/eazybi-reports-and-charts-for-confluence?hosting=datacenter","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ff44e20b-19e4-43b4-835a-88c27c28296e","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"9b16bc2f-fc5e-4886-9781-6db87bd486b0"},{"id":"4592d652-bb2d-4ab9-8720-08fe80de0dc4","name":"Backbone","targetId":"9b16bc2f-fc5e-4886-9781-6db87bd486b0"},{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"9b16bc2f-fc5e-4886-9781-6db87bd486b0"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"9b16bc2f-fc5e-4886-9781-6db87bd486b0"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9b16bc2f-fc5e-4886-9781-6db87bd486b0"},{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"9b16bc2f-fc5e-4886-9781-6db87bd486b0"}],"recentChangeFlags":null},{"id":"92a95cc4-267e-4619-bc66-909a4cb21ca9","uri":"https://docs.eazybi.com/","name":"docs.eazybi.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f2758adc-2d0b-4de3-aff8-135256b5beec","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"92a95cc4-267e-4619-bc66-909a4cb21ca9"},{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"92a95cc4-267e-4619-bc66-909a4cb21ca9"},{"id":"4592d652-bb2d-4ab9-8720-08fe80de0dc4","name":"Backbone","targetId":"92a95cc4-267e-4619-bc66-909a4cb21ca9"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"92a95cc4-267e-4619-bc66-909a4cb21ca9"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"92a95cc4-267e-4619-bc66-909a4cb21ca9"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"d99973a0-5808-4d62-976b-c4733fbc75fd","p1MaxCents":300000,"p1MinCents":300000,"p2MaxCents":120000,"p2MinCents":120000,"p3MaxCents":40000,"p3MinCents":40000,"p4MaxCents":15000,"p4MinCents":15000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":3000,"max":3000},"2":{"min":1200,"max":1200},"3":{"min":400,"max":400},"4":{"min":150,"max":150},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"aa0555a2-8469-4672-9589-35ba734149db","code":"eazybi","state":"in_progress","endsAt":null,"bountyId":"c9747e90-681f-4052-8f4a-50a0a67d33fd","startsAt":"2019-10-29T17:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/bec7/6531/1295ef20/ce67bbcbf8cc6a940cf9774c221798fd_eazybilogo.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2019-10-29T17:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/eazybi","changelogs":"/engagements/eazybi/changelog","submissions":null,"announcements":"/engagements/eazybi/announcements","hallOfFame":"/engagements/eazybi/hall_of_fames","crowdstream":"/engagements/eazybi/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/eazybi/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=eazybi\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/eazybi/engagement_subscribers","engagementChangelogsUrl":"/engagements/eazybi/changelog","publishedAt":"2026-03-25T11:18:52.328Z","engagementChangelogUrl":"/engagements/eazybi/changelog/d910ea72-d174-432c-ad2f-11df1a3b729a","createUserFeedbacksUrl":"/engagements/eazybi/feedbacks","engagementCrowdstreamUrl":"/engagements/eazybi/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}