{"id":"e88a4cbf-ca2a-4076-93c0-9f76b0e26119","engagementId":"b628df54-ea06-45e9-80ac-133c1a7e3ad7","data":{"brief":{"id":"60323e88-1625-460b-bab3-6932cd7b07c5","name":"EPAM Systems Managed Bug Bounty Program","tagline":"EPAM Systems leads the industry in digital and physical product development and digital platform engineering services. Please submit your findings to this Bug Bounty Program.","description":"\u003ch2\u003eAbout EPAM\u003c/h2\u003e\n\n\u003cp\u003eEPAM's global teams serve customers in more than 35 countries across North America, Europe, Asia, and Australia. As a recognized market leader in multiple categories among top global independent research agencies, EPAM was one of only four technology companies to appear on the Forbes 25 Fastest Growing Public Tech Companies list every year of publication since 2013 and has ranked as the top IT services company on Fortune's 100 Fastest-Growing Companies list in 2019 and 2020. We value collaboration, work in partnership with our customers, and strive for the highest standards of excellence. We're remotely supporting operations for hundreds of clients worldwide in today's market conditions.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect, and EPAM Systems believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our applications and infrastructure. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases, a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher and the opportunity to appeal and make a case for a higher priority._\u003c/p\u003e\n\n\u003ch2\u003eMain Guidelines, read closely!\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eethics.epam.com is out of the program's scope. Do not perform any testing for this target!\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eEvery request must include the X-Bugcrowd header with Bugcrowd username, for e.g: Bugcrowd-\u0026lt;Username\u0026gt;\u003c/li\u003e\n\u003cli\u003eMust use the Bugcrowd email alias [username]@bugcrowdninja.com. \u003c/li\u003e\n\u003cli\u003eAutomation against form submissions is not allowed and can lead to a ban from the program.\u003c/li\u003e\n\u003cli\u003eDo not degrade EPAM's user experience, disrupt production systems, or destroy data during security testing.\u003c/li\u003e\n\u003cli\u003ePlease do not test requests for account removal at https://anywhere.epam.com/en/contact-us. We won't accept this as a valid submission\u003c/li\u003e\n\u003cli\u003eRead the program's scope carefully!\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eViolation of any point above will lead to an immediate program ban!\u003c/p\u003e\n\n\u003ch2\u003eProhibited Activity\u003c/h2\u003e\n\n\u003cp\u003eAutomated vulnerability scanners. We need your brainpower, not your processing power.\u003c/p\u003e","industryTagId":"0e55e259-dfc5-4952-99de-5e094e40609a","targetsOverview":"\u003chr\u003e\n\n\u003ch3\u003eEligibility:\u003c/h3\u003e\n\n\u003cp\u003e\u003cstrong\u003eFor EPAM employees:\u003c/strong\u003e Usage of EPAM credentials is not allowed.\u003c/p\u003e\n\n\u003ch3\u003eCredentials:\u003c/h3\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e \u003cbr\u003e\nDo not use EPAM corporate credentials or any leaked/found/unauthorized credentials to access in-scope systems. Report exposed credentials as a finding — do not use them. Issues reachable only through such access are out of scope.\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eDifferent types of injections\u003c/li\u003e\n\u003cli\u003eRCE\u003c/li\u003e\n\u003cli\u003eSSRF\u003c/li\u003e\n\u003cli\u003eXXE Injections\u003c/li\u003e\n\u003cli\u003ePath traversal\u003c/li\u003e\n\u003cli\u003eStored-cross or reflected site scripting (not self-XSS)\u003c/li\u003e\n\u003cli\u003ePII leakage issues\u003c/li\u003e\n\u003cli\u003eSecurity misconfigurations with demonstrated security impact\u003c/li\u003e\n\u003cli\u003eAny other vulnerabilities that will give the possibility for threat actors to read files from the server/execute commands/retrieve sensitive information\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cp\u003eTo avoid confusion, we kindly ask you to get familiar with the scope of our program before submitting any reports.\u003c/p\u003e\n\n\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of EPAM Systems not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you identify a security vulnerability on a target that is not in scope but demonstrably belongs to EPAM Systems and has a security impact, you can report it to this program. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAvoid testing any contact forms on epam.com *.epam.com\u003c/li\u003e\n\u003cli\u003ePlease do not report information disclosure at https://investors.epam.com/. EPAM is a public company, and financial information is publicly available to our customers and investors.\u003c/li\u003e\n\u003cli\u003eAny vulnerabilities only reachable by authenticating with leaked, found, guessed, or otherwise unauthorized credentials (including EPAM corporate credentials). Discovering exposed credentials should be reported as a finding; using them to access in-scope systems is out of scope and ineligible for reward.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope Vulnerabilities\u003c/h2\u003e\n\n\u003cp\u003eThe following issues are considered out-of-scope for our bug bounty program unless they demonstrate a tangible security impact:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eClickjacking:\u003c/strong\u003e  Attacks that trick users into clicking on something other than what they intended.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eBroken Link Hijacking:\u003c/strong\u003e  Cases where broken or misdirected links are exploited.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eFirebase API Key Exposure:\u003c/strong\u003e  Leaks of Firebase API keys without demonstrated security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSession Management Issues:\u003c/strong\u003e  - Session expiration problems after logout.  - Inadequate session timeout lengths or account lockout policies.  - Failure to invalidate sessions on password reset.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eKnown Vulnerable Components:\u003c/strong\u003e  Use of components with known vulnerabilities without a working proof-of-concept exploit.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eBusiness Logic Flaws:\u003c/strong\u003e  Issues in business processes that do not have a demonstrable security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eUnrestricted File Uploads:\u003c/strong\u003e  File upload issues that lack a demonstrated security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAPI Key Leaks:\u003c/strong\u003e  Disclosure of Google Maps/MapBox API keys.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eExternal Service Interactions:\u003c/strong\u003e  Interactions with external services that do not demonstrate a security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePassword Policies:\u003c/strong\u003e  Issues related solely to password complexity or length.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCross-Site Scripting (XSS):\u003c/strong\u003e  Post-based XSS without a demonstrated security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eServer-Side Request Forgery (SSRF):\u003c/strong\u003e  Blind SSRF vulnerabilities without demonstrated security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSelf-XSS:\u003c/strong\u003e  Self-inflicted XSS that does not present a realistic threat.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCross-Site Request Forgery (CSRF):\u003c/strong\u003e  On unauthenticated forms or forms that do not perform sensitive actions.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eMITM or Physical Access Attacks:\u003c/strong\u003e  Attacks requiring man-in-the-middle techniques or physical access to a user’s device.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eKnown Vulnerable Libraries:\u003c/strong\u003e  Previously reported vulnerabilities without a working exploit.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCSV Injection:\u003c/strong\u003e  Comma-Separated Values injection without a demonstrated vulnerability.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSSL/TLS Configuration Issues:\u003c/strong\u003e  Deviations from best practices in SSL/TLS settings.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDenial of Service (DoS):\u003c/strong\u003e  Any activities that might lead to service disruption.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eContent Spoofing / Text Injection:\u003c/strong\u003e  Issues where an attack vector isn’t clearly demonstrated (e.g., inability to modify HTML/CSS).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eRate Limiting / Brute Force:\u003c/strong\u003e  Problems related to rate limiting or brute force attacks without a tangible impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eContent Security Policy (CSP):\u003c/strong\u003e  Non-adherence to established CSP best practices.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCookie Security:\u003c/strong\u003e  Missing \u003ccode\u003eHttpOnly\u003c/code\u003e or \u003ccode\u003eSecure\u003c/code\u003e flags on cookies.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eEmail Security Practices:\u003c/strong\u003e  Issues with SPF, DKIM, or DMARC records (e.g., invalid, incomplete, or missing).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eOutdated Browser Vulnerabilities:\u003c/strong\u003e  Issues that only affect browsers more than 2 stable versions behind the latest release.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eInformation Disclosure:\u003c/strong\u003e  - Software version and banner disclosures.  - Descriptive error messages or headers (e.g., stack traces or server errors).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePublic Zero-Day Vulnerabilities:\u003c/strong\u003e  Zero-day vulnerabilities that have had an official patch for less than one month (evaluated on a case-by-case basis).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eRecently Patched or Disclosed Vulnerabilities:\u003c/strong\u003e Publicly known vulnerabilities that have had an official patch available for less than one month (evaluated on a case-by-case basis).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eTabnabbing:\u003c/strong\u003e  Vulnerabilities related to tabnabbing attacks.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eUnlikely User Interaction:\u003c/strong\u003e  Issues requiring highly improbable user behavior to be exploited.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eHTML Injection:\u003c/strong\u003e  Without a demonstrated security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCRLF Injection:\u003c/strong\u003e  Without a demonstrated security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAutomated Scanner Reports:\u003c/strong\u003e  Findings solely reported by automated tools.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDDoS/DoS Attacks:\u003c/strong\u003e  Denial-of-service attacks or related issues.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCache Poisoning:\u003c/strong\u003e  Without demonstrated security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCDN Bypass Techniques:\u003c/strong\u003e  - CloudFront bypass leading to origin IP disclosure.  - Cloudflare bypass leading to origin IP disclosure.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSharePoint Services:\u003c/strong\u003e  Exposed SharePoint web services without a demonstrable impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eRobots.txt/Sitemap.xml Issues:\u003c/strong\u003e  Findings that do not demonstrate a security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eFrontPage Configuration Disclosure:\u003c/strong\u003e  Exposure of configuration information without demonstrated impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eUser/Email Enumeration:\u003c/strong\u003e  Issues that simply enumerate users or emails.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCleartext Password Transmission:\u003c/strong\u003e  Sending passwords over HTTP instead of HTTPS.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDependency Confusion:\u003c/strong\u003e  Vulnerabilities arising from dependency misconfigurations.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eEXIF Data Exposure:\u003c/strong\u003e  Failure to strip geolocation data from uploaded images/documents.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eWordPress Issues:\u003c/strong\u003e  - Disclosure or enumeration of WordPress users.  - Enabled \u003ccode\u003exmlrpc.php\u003c/code\u003e on WordPress installations.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCache-Control Misconfigurations:\u003c/strong\u003e  Improper or missing cache-control headers.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDomain takeover issues  have been identified on subdomains under *.lab.epam.com and domains including *.projects.epam.com.\u003c/strong\u003e These zones are used for non-production  sandboxed environments and demos.\n\u003cem\u003ePlease note that to be eligible for a bounty, vulnerabilities must clearly demonstrate a tangible security impact.\u003c/em\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut-of-Scope Mobile Vulnerabilities\u003c/h2\u003e\n\n\u003cp\u003eThe following mobile issues are considered out-of-scope for our bug bounty program unless they demonstrate a tangible security impact:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eGoogle Maps API Key Leakage:\u003c/strong\u003e Disclosure of Google Maps API keys.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eBroken Link Hijacking:\u003c/strong\u003e Exploitation of broken or misdirected links.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eFirebase API Key Exposure:\u003c/strong\u003e Leaks of Firebase API keys without demonstrated security impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eReverse Engineering:\u003c/strong\u003e Decompiling or reverse engineering an app.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSQL Injection in Content Providers:\u003c/strong\u003e SQL injection vulnerabilities in content providers that do not result in a privilege escalation.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eRoot Detection Issues:\u003c/strong\u003e Cases where the application does not detect if it is on a rooted device.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eRooted/Jailbroken/Emulator-Only Issues:\u003c/strong\u003e Vulnerabilities that only occur on rooted/jailbroken devices or emulators.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePhishing and Social Engineering:\u003c/strong\u003e Attacks relying on phishing or social engineering techniques.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eExcessive Permissions:\u003c/strong\u003e Instances where an app requests excessive permissions without demonstrable risk.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eHardware Attacks:\u003c/strong\u003e Vulnerabilities requiring physical hardware attacks.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDeveloper Mode Bugs:\u003c/strong\u003e Issues related to developer mode that do not impact security.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eNon-Eligible Device Versions:\u003c/strong\u003e Reports concerning device versions that are not supported.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eTapjacking:\u003c/strong\u003e Vulnerabilities related to tapjacking attacks.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSensitive Data in Screenshots:\u003c/strong\u003e Instances where screenshots display sensitive application data.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCertificate Pinning:\u003c/strong\u003e Misconfigurations or issues related to certificate pinning.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eBinary Protection Absence:\u003c/strong\u003e Lack of binary protection measures, such as the absence of a Stack Canary.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eExtensive User Interaction Requirements:\u003c/strong\u003e Vulnerabilities requiring extensive user interaction.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eExposure of Non-Sensitive Data:\u003c/strong\u003e Cases where only non-sensitive data is exposed on the device.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eThird-Party Library Vulnerabilities:\u003c/strong\u003e Vulnerabilities in third-party libraries without showing specific impact on the target application.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDeprecated/Banned API Usage:\u003c/strong\u003e Use of deprecated or banned APIs.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSensitive Info in Logs:\u003c/strong\u003e Exposure of sensitive information in logs from staging or test builds.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eExported Components:\u003c/strong\u003e Exporting an activity, receiver, content provider, or service is not considered a vulnerability unless it can be used to gain unauthorized access to application data or functionality.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support\u003c/a\u003e before going further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"30014a3a-3f02-47ef-9edf-38a7913853ae","name":"In Scope Targets - Tier 1","targets":[{"id":"a1b05640-a9a0-4d2e-a5c2-e61f80ec94ae","uri":"https://www.epam.com/","name":"*.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1dad4445-757a-4d78-b961-2e12f5a87857","sortOrder":0},"sortOrder":0,"tags":[{"id":"187a0132-af2c-45e1-b4af-77ac6117b9dc","name":"Adobe Experience Manager","targetId":"a1b05640-a9a0-4d2e-a5c2-e61f80ec94ae"},{"id":"3585ef4a-cd09-429b-ad25-5777064e59c5","name":"Moment.js","targetId":"a1b05640-a9a0-4d2e-a5c2-e61f80ec94ae"},{"id":"53917c1d-52c8-41f3-86f5-166e787ece8f","name":"Select2","targetId":"a1b05640-a9a0-4d2e-a5c2-e61f80ec94ae"},{"id":"9dd4899d-3a63-4126-8c83-c1fc1de50c25","name":"Amazon Cloudfront","targetId":"a1b05640-a9a0-4d2e-a5c2-e61f80ec94ae"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"a1b05640-a9a0-4d2e-a5c2-e61f80ec94ae"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a1b05640-a9a0-4d2e-a5c2-e61f80ec94ae"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"bf7d255e-6845-4bfc-a770-02542697fef7","p1MaxCents":100000,"p1MinCents":100000,"p2MaxCents":60000,"p2MinCents":60000,"p3MaxCents":30000,"p3MinCents":30000,"p4MaxCents":10000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eAvoid testing any contact forms on *.epam.com and epam.com. Third-level subdomains at *.epam.com and epam.com are valid targets for Tier 1 bounties.\u003c/p\u003e","rewardRangeData":{"1":{"min":1000,"max":1000},"2":{"min":600,"max":600},"3":{"min":300,"max":300},"4":{"min":100,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"897b769b-1064-4353-8f8c-f02ad126f0ac","name":"Subdomain takeover - Tier 0","targets":[{"id":"49c5158b-6b67-43fe-a1ab-ccc027c7b48c","uri":"https://*.epam.com","name":"Subdomain takeover","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5193cfd8-0cfa-4c7a-b72c-cba0738e2c38","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"6b3cf6e2-436c-466e-9b2e-3d7c2a07a5f3","p1MaxCents":15000,"p1MinCents":15000,"p2MaxCents":15000,"p2MinCents":15000,"p3MaxCents":15000,"p3MinCents":15000,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eSubdomains under  *.lab.epam.com,  *.projects.epam.com, and  *.opensource.epam.com are  out of scope and will generally not be considered for rewards. \u003c/p\u003e\n\n\u003cp\u003eSubdomains under *.gcp.cloudapp.epam.com are considered out of scope for reward eligibility.\u003c/p\u003e\n\n\u003cp\u003eThese subdomains are dynamically provisioned as part of our development and infrastructure automation processes (e.g., via GKE), and are subject to frequent creation and teardown. As such, they may appear vulnerable to subdomain takeover due to normal lifecycle operations, not due to a misconfiguration.\u003c/p\u003e\n\n\u003cp\u003eBecause of this ephemeral nature, subdomain takeovers at *.gcp.cloudapp.epam.com will not be rewarded, unless:\u003cbr\u003e\n    • A working proof-of-concept remains live and verifiable for an extended period of time, and\u003cbr\u003e\n    • The issue can be clearly demonstrated as a genuine misconfiguration rather than a result of intended infrastructure behavior.\u003c/p\u003e\n\n\u003cp\u003eAdditionally, any domain that is \u003cstrong\u003enot under *.epam.com\u003c/strong\u003e is strictly out of scope.\u003c/p\u003e","rewardRangeData":{"1":{"min":150,"max":150},"2":{"min":150,"max":150},"3":{"min":150,"max":150},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"9c9534bb-c4cb-481a-9e6e-47d2f3d95c8c","name":"In Scope Targets - Tier 2","targets":[{"id":"bac2b6e9-9284-4f14-b25b-21ec4f08a88c","uri":"https://projects.epam.com","name":"*.projects.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6e056cb1-9a4b-4499-94fe-b1c9c8356539","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"bac2b6e9-9284-4f14-b25b-21ec4f08a88c"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":{"id":"c3034006-b9ee-48a9-96ac-b56e3d7719de","p1MaxCents":50000,"p1MinCents":50000,"p2MaxCents":25000,"p2MinCents":25000,"p3MaxCents":null,"p3MinCents":null,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eAny level subdomains at *.projects.epam.com are valid targets for Tier 2 bounties. P3 and P4 submissions will be accepted as valid submissions but won\u0026#39;t be rewarded with bounties.\u003c/p\u003e","rewardRangeData":{"1":{"min":500,"max":500},"2":{"min":250,"max":250},"3":{"min":null,"max":null},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"0cdd0999-3615-41bd-b02a-5eac6551e189","name":"In Scope Targets - Tier 3","targets":[{"id":"ed4923b9-6430-4bd1-b73c-438ee22a82d6","uri":"https://lab.epam.com","name":"*.lab.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"fd05c533-8761-4f83-b347-5e45fd13f765","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ed4923b9-6430-4bd1-b73c-438ee22a82d6"}],"recentChangeFlags":null},{"id":"06b2effb-bd72-4384-bbb3-6a3fbb4fd68a","uri":"https://opensource.epam.com","name":"*.opensource.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4ecee86e-25c1-4b4b-a4cb-978af713a3a5","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"06b2effb-bd72-4384-bbb3-6a3fbb4fd68a"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":3,"description":null,"rewardRange":{"id":"f5a1031e-0558-4e96-919d-a1aa287326b8","p1MaxCents":30000,"p1MinCents":30000,"p2MaxCents":15000,"p2MinCents":15000,"p3MaxCents":null,"p3MinCents":null,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eAny level subdomains at *.lab.epam.com and *.opensource.epam.com are valid targets for Tier 3 bounties. P3 and P4 submissions will be accepted as valid submissions but won\u0026#39;t be rewarded with bounties. Everything under *.lab.epam.com and *.opensource.epam.com is a development environment or project planned to be released to the open-source, and please consider that fake PII data can be used there.\u003c/p\u003e","rewardRangeData":{"1":{"min":300,"max":300},"2":{"min":150,"max":150},"3":{"min":null,"max":null},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"b847ea90-3df5-47db-aa03-bb5c580c9008","name":"In Scope Targets - Tier 4","targets":[{"id":"c87b94f2-d009-4ea9-a200-320277942b9d","uri":"","name":"*.emakina.nl ","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e006ba77-aad6-4c4f-a3af-1a48b2dac47e","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"7e069adc-d9fa-4cdb-a06c-0e7e84ea0ae9","uri":"","name":"*.emakina.group","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b5a2c57e-7c8d-44c6-bb69-ba6d28a77e62","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"864620b0-1d69-497f-aa50-576d594b9b31","uri":"","name":"*.emakina.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3393ebec-a5ec-47c4-ac4d-7dd71066050e","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"248e0a3f-7c51-42b0-995a-5a65f6d0e5fc","uri":"","name":"*.emakina.ch","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d54318bb-cf6c-4153-8737-5ef10a326203","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"2ed2dea7-53ba-4349-928b-cba52af836fe","uri":"","name":"*.emakina.fr","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f4a26e72-e844-425d-b69e-bebf8fbb2134","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"d6487422-ac2f-431a-ae0d-4e6c47a32cc3","uri":"","name":"*.emakina.us","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5afe8888-595e-4965-87a6-7bdd6c6b9400","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"4bc6e090-54ae-47c2-822c-a595c2c1c6d9","uri":"","name":"*.emakina.at","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ac64b7e0-a579-446b-9638-07ac89e1b92c","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":4,"description":null,"rewardRange":{"id":"3d98b5c6-73f4-4e69-b52b-18f03dc0f5cd","p1MaxCents":50000,"p1MinCents":50000,"p2MaxCents":30000,"p2MinCents":30000,"p3MaxCents":15000,"p3MinCents":15000,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eAny level subdomains are valid targets for Tier 4 bounties. P4 submissions will be accepted as valid submissions but won\u0026#39;t be rewarded with bounties. \u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eDo not perform any testing on:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ehttps://www.emakina.nl/\u003c/li\u003e\n\u003cli\u003ehttps://www.emakina.group/\u003c/li\u003e\n\u003cli\u003ehttps://www.emakina.com/\u003c/li\u003e\n\u003cli\u003ehttps://www.emakina.ch/\u003c/li\u003e\n\u003cli\u003ehttps://www.emakina.fr/\u003c/li\u003e\n\u003cli\u003ehttps://www.emakina.us/\u003c/li\u003e\n\u003cli\u003ehttps://www.emakina.at/\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eImportant:\u003c/strong\u003e Avoid testing any contact forms. Open redirect, host header injection vulnerabilities are outside the scope of Tier 4 targets.\u003c/p\u003e","rewardRangeData":{"1":{"min":500,"max":500},"2":{"min":300,"max":300},"3":{"min":150,"max":150},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"a817cf0e-2d54-4eeb-9c93-c3fd60a2a517","name":"Open redirect","targets":[{"id":"6711d4c2-c95a-4917-9e0d-abcd4fca4a71","uri":"","name":"open redirect at *.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"84d81f0d-0ade-47bd-a46c-ef569f3880ae","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":5,"description":null,"rewardRange":{"id":"03b49fb2-f953-4ba5-a8c6-868d8b901d1a","p1MaxCents":10000,"p1MinCents":10000,"p2MaxCents":10000,"p2MinCents":10000,"p3MaxCents":10000,"p3MinCents":10000,"p4MaxCents":10000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eOpen redirect at 3rd level subdomain *.epam.com\u003c/p\u003e","rewardRangeData":{"1":{"min":100,"max":100},"2":{"min":100,"max":100},"3":{"min":100,"max":100},"4":{"min":100,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"cff9bd0a-5fd8-4c61-8773-d7b46e8014bc","name":"Open redirect - Tier #1","targets":[{"id":"8b4ade11-fd3b-4472-9cf3-f5408e1a90cb","uri":"","name":"Open redirect at *.projects.epam.com, *.lab.epam.com, *.opensource.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"bb42cccb-3a31-492f-afb6-247fd13b34a0","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":6,"description":null,"rewardRange":{"id":"62271cda-5d99-4814-899f-2a41e240ad63","p1MaxCents":5000,"p1MinCents":5000,"p2MaxCents":5000,"p2MinCents":5000,"p3MaxCents":5000,"p3MinCents":5000,"p4MaxCents":5000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eOpen redirect at:\u003cbr\u003e\n*.projects.epam.com\u003cbr\u003e\n*.lab.epam.com\u003cbr\u003e\n*.opensource.epam.com\u003c/p\u003e","rewardRangeData":{"1":{"min":50,"max":50},"2":{"min":50,"max":50},"3":{"min":50,"max":50},"4":{"min":50,"max":50},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"e26e8822-6afa-4973-b76c-77e88fe4226f","name":"In Scope - Points Only","targets":[{"id":"d66f5e38-f6c5-4bba-a3dc-2547976f7c54","uri":"","name":"In Scope - Points only","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9b4c055c-9d14-447e-a0ef-a0b961966c1e","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":7,"description":null,"rewardRange":null,"descriptionHtml":"\u003cul\u003e\n\u003cli\u003eLeaks of credentials and confidential information from malware logs/dumps/intelligence services/public sources would be accepted as valid issues but won\u0026#39;t be rewarded with a bounty.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"ab03e2d1-c72f-4fed-bffa-37461012135c","name":"Out of Scope Targets","targets":[{"id":"ead7d336-0258-4a67-9a7d-2e0b7f66336a","uri":"https://ethics.epam.com/","name":"ethics.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2f6a7761-50cf-4b74-9eb8-295ad8bec440","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"e6742d0c-3822-4262-a844-9715cc5fea07","uri":"https://profile.epam.com","name":"profile.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4b3d5649-ec51-465b-b5fa-8b15a161df42","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"90d70fd9-30fd-4033-946a-3fa74d26d48c","uri":"https://carbon.epam.com/","name":"carbon.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5c2eb8f4-3559-4428-8fa2-6b273750d18a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"003104b8-6fb5-4bad-820c-da09bf6a875d","uri":"https://www.infongen.com/","name":"infongen.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b8fdd5f1-c4a3-4513-b670-6cdd5644ffc4","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"0c8945e6-3a6b-4e16-aa46-46dc8721c899","uri":"http://ebn.epam.com/","name":"ebn.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d3b40e6c-718a-4856-8c84-3567ba38c7b0","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"2fd3b3c3-3ce5-4507-a488-bd60d2ac5159","uri":"https://solutionshub.epam.com/","name":"solutionshub.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5286432d-caff-48ff-967b-386d60783686","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"a819b131-dd8e-4476-a26d-23634827209c","uri":"https://www.telescopeai.com/","name":"telescopeai.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7341d624-7ff3-4e1b-bb19-73a18ef1fb0e","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"fe4d85b9-85ec-4768-8fd5-b4d75103fc4a","uri":"https://wearecommunity.io/","name":"wearecommunity.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5b3609ae-0fa7-42fd-bfb2-71ff4db6e935","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"319d24e2-4058-4abe-a892-28e1894fa861","uri":"https://cami.lab.epam.com/","name":"cami.lab.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"bc36575a-b4c2-465a-9f6f-2bb03cccc9ad","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"c87560a2-efdb-4b1a-9922-83d7d33633c5","uri":"https://ellie.lab.epam.com/","name":"ellie.lab.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"14f247bf-804e-4daa-8671-e75a92b4a550","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"3408e8d3-e788-4b81-932e-2d88b132b32a","uri":"https://apex.lab.epam.com/","name":"apex.lab.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7cf0028d-f6f1-4825-85b3-ea7623419e7a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"3083bba5-055e-421d-a218-17f741f61d9e","uri":"https://investors.epam.com/","name":"investors.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c4ef7645-2668-4e30-92e7-6d7e1e365309","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"4604f5af-5d6a-4975-b6bd-8d7c0b1131f6","uri":"https://ecsd00300769.epam.com/","name":"ecsd00300769.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"27fbe6d1-b0e9-4bc7-96f4-801b9869d2a8","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"fb2e4ed0-8216-4d4e-900f-1c0823484f2d","uri":"https://display.epam.com/","name":"display.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7782d95e-0149-44f3-a161-6aca79909222","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"818b2ef5-50ff-4296-bdf7-3f72ea1442d9","uri":"https://info.epam.com","name":"info.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0ccfc7e3-b235-4a21-bea6-96456df2ba55","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"09bf1f08-6955-442f-bea4-1024832ca4e7","uri":"https://admin-ui.preship.gcp.gnrg-osdu.projects.epam.com","name":"admin-ui.preship.gcp.gnrg-osdu.projects.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1aeb9a17-a4b8-43a7-a19b-2682d53f53a9","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"444883c3-1ec2-4f08-8639-8fcf279bbdb8","uri":"https://support.epam.com/","name":"support.epam.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"fdea97ed-0b57-4e0e-a510-4d827a82ddbb","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"80f98c61-d74a-4887-bd57-de0320ef8a62","uri":"https://customersupport.epam.com/","name":"customersupport.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"888dbfba-c525-48fc-9313-96ca1770e810","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"aa47d079-ab83-466e-bf24-981f88f40ff3","uri":"https://supportnow.epam.com/","name":"supportnow.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1640f5a2-c547-4d39-acf2-c329200eaa6d","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"d9da23b3-3a87-4fc5-b05b-60fcac04b5f4","uri":"https://anywhere.epam.com/","name":"anywhere.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"cfc358a7-2a13-477d-9b82-550c274f59bb","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"de68a6de-d81f-4917-8ead-d1899a8d3c2c","uri":"https://*buddybot.lab.epam.com","name":"*.buddybot.lab.epam.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e4a1e5af-c35a-4521-b7fd-eb3eb088f28d","sortOrder":20},"sortOrder":20,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":8,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"b628df54-ea06-45e9-80ac-133c1a7e3ad7","code":"epam-mbb-og","state":"in_progress","endsAt":null,"bountyId":"85100c0d-bbef-4d7a-9ae7-776b2ed25a28","startsAt":"2023-09-28T12:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Business Management","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/10e3/be27/8c14ec20/f77dad8a59aa5c5d49d27a273a7c82c1_epam.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2023-09-28T12:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/epam-mbb-og","changelogs":"/engagements/epam-mbb-og/changelog","submissions":null,"announcements":"/engagements/epam-mbb-og/announcements","hallOfFame":"/engagements/epam-mbb-og/hall_of_fames","crowdstream":"/engagements/epam-mbb-og/crowdstream"},"announcementsCount":17,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/epam-mbb-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=epam-mbb-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/epam-mbb-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/epam-mbb-og/changelog","publishedAt":"2026-08-26T12:28:52.496Z","engagementChangelogUrl":"/engagements/epam-mbb-og/changelog/e88a4cbf-ca2a-4076-93c0-9f76b0e26119","createUserFeedbacksUrl":"/engagements/epam-mbb-og/feedbacks","engagementCrowdstreamUrl":"/engagements/epam-mbb-og/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}