{"id":"144e2dcb-9308-4884-8972-b2430779bf1e","engagementId":"7fd12e7d-b147-4eb6-8832-164bdb6d647f","data":{"brief":{"id":"57861cb8-bb46-4861-8d3a-181ebec618b7","name":"EXIM - Vulnerability Disclosure Program","tagline":"Submit your report here.","description":"\u003cp\u003eNo technology is perfect and The Export-Import Bank of the United States (EXIM) believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our web apps. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"2a38890b-c88e-4bc0-8db0-02059f3fafe6","targetsOverview":"\u003ch2\u003eAuthorization\u003c/h2\u003e\n\n\u003cp\u003eSecurity researchers must comply with all applicable Federal, State, and local laws in connection with the security research activities or other participation in this Vulnerability Disclosure Program.\u003c/p\u003e\n\n\u003cp\u003eEfforts made in good faith to comply with this policy during all security research will be considered authorized. EXIM will work with the researcher to understand and quickly resolve issues and will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against the security researcher for research conducted in accordance with this policy, EXIM will reaffirm this authorization.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eApplicability and Scope\u003c/h2\u003e\n\n\u003cp\u003eThis policy is for security researchers interested in reporting system security vulnerabilities and is intended for authorized EXIM publicly available systems/services only. This policy applies to anyone wishing to conduct vulnerability discovery activities, including research and testing conducted on EXIM’s publicly available systems/services within the EXIM.gov domain. This also includes the registered domain name EXIM.gov.\u003c/p\u003e\n\n\u003cp\u003eThough EXIM develops and maintains other internet-accessible systems or services, we ask that active research and testing be conducted only on the systems and services covered by the scope of this EXIM policy. We will increase the scope of this policy over time.\u003c/p\u003e\n\n\u003cp\u003eIf there is uncertainty regarding the scope, please contact VDP@exim.gov.\u003c/p\u003e\n\n\u003cp\u003eAdditionally, vulnerabilities found in systems from non-EXIM entities are outside of this policy’s scope and should be reported directly to the non-EXIM entity according to their disclosure policy. If there is uncertainty regarding the scope of a system, contact VDP@exim.gov.\u003c/p\u003e\n\n\u003cp\u003eWhile EXIM Office of the Chief Information Officer (OCIO) is responsible for the development and maintenance for various internet-accessible systems or services, research and testing should only be conducted on the systems and services covered by the scope of this policy. The scope of this policy is subject to change. Please contact VDP@exim.gov if questions arise regarding systems not currently in scope.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eGuidelines\u003c/h2\u003e\n\n\u003cp\u003eUnder this policy, “research” means activities in which you:\u003c/p\u003e\n\n\u003cp\u003e• Notify EXIM as soon as possible after the discovery of any real or potential security issue(s).\u003cbr\u003e\n• Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.\u003cbr\u003e\n• Only use exploits to the extent necessary to confirm a vulnerability’s presence. Do not use an exploit to compromise or exfiltrate data, establish persistent command line access, or use the exploit to pivot to other systems.\u003cbr\u003e\n• Do not submit a high volume of low-quality reports.\u003c/p\u003e\n\n\u003cp\u003eUpon the discovery of a vulnerability or sensitive data (including personally identifiable information, financial information or proprietary information or trade secrets of any party):\u003c/p\u003e\n\n\u003cp\u003e• ALL tests must be stopped.\u003cbr\u003e\n• Notify EXIM immediately.\u003cbr\u003e\n• Do Not disclose this data to anyone.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eReporting a Vulnerability\u003c/h2\u003e\n\n\u003cp\u003eWhen submitting a vulnerability, the security researcher acknowledges that there is no expectation of payment and that any future pay claims against the U.S. Government related to the submission have been waived.\u003c/p\u003e\n\n\u003cp\u003eWhen contact information is shared, EXIM commits to coordinating with the security researcher in a transparent and timely manner:\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eWithin three (3) business days, EXIM will acknowledge that the report has been received.\u003c/li\u003e\n\u003cli\u003eWithin (15) business days, EXIM will confirm the existence of the vulnerability and provide further discussion on findings, resolutions and/or issues or challenges that may delay resolution.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eVulnerability Reports\u003c/h2\u003e\n\n\u003cp\u003eTo report identified vulnerabilities, security researchers must:\u003c/p\u003e\n\n\u003cp\u003e• Submit vulnerability reports to https://bugcrowd.com/exim-vdp\u003cbr\u003e\n• Describe the location the vulnerability was discovered and the potential impact of exploitation.\u003cbr\u003e\n• Offer a detailed description of the steps needed to reproduce the vulnerability (proof of concept scripts or screenshots).\u003cbr\u003e\n• Submit vulnerability reports, anonymously, if desired. If a security researcher provides EXIM with an email address, EXIM will acknowledge submitted reports within three (3) business days.\u003cbr\u003e\n• Keep confidential any information about discovered vulnerabilities for up to (90) calendar days after being notified by EXIM.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCoordinated Disclosure\u003c/h2\u003e\n\n\u003cp\u003eEXIM is committed to patching vulnerabilities within (90) days or less and disclosing the details of those vulnerabilities when patches are published. We believe that public disclosure of vulnerabilities is an essential part of the vulnerability disclosure process, and that one of the best ways to make software better is to enable everyone to learn from each other’s mistakes.\u003c/p\u003e\n\n\u003cp\u003eAt the same time, we believe that disclosure in the absence of a readily available patch tends to increase risk rather than reduce it, and so we ask that security researchers refrain from sharing reports with others, or releasing reports to the public, while patching is occurring. If there is a need to inform others of the submitted report before the patch is available, please coordinate with EXIM at VDP@exim.gov prior to release for assessment.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eUse of Vulnerability Reports\u003c/h2\u003e\n\n\u003cp\u003eInformation submitted under this policy shall be used by EXIM for defensive cybersecurity purposes (i.e. to mitigate or remediate vulnerabilities). If an issue has been reported and determined to be both within the program scope and determined to be a valid security issue, EXIM will validate the finding(s) and the security researcher can disclose the vulnerability after a resolution has been issued. The details within the Vulnerability Intake form may be submitted to an independent third-party vendor for evaluation and handling\u003c/p\u003e\n\n\u003ch2\u003eInformation Sharing\u003c/h2\u003e\n\n\u003cp\u003eInformation submitted under this policy may be shared for defensive cybersecurity means:\u003cbr\u003e\nIf findings submitted include newly discovered vulnerabilities that affect users of a product or service outside of EXIM, EXIM may share vulnerability reports with DHS CISA, where it will be handled under DHS CISA’s coordinated vulnerability disclosure process. EXIM retains the right to share this information with DHS CISA and other applicable organizations, as needed.\u003c/p\u003e\n\n\u003cp\u003ePersonal information pertinent to the security researcher will not be disclosed or shared without the researcher’s express written permission.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTesting Methods\u003c/h2\u003e\n\n\u003cp\u003eEXIM requires that security researchers comply with authorized test methods/activities to access systems within the publicly available EXIM.gov domains, and not perform any unauthorized test methods/activities.\u003c/p\u003e\n\n\u003ch2\u003eAuthorized Testing Methods/Activities\u003c/h2\u003e\n\n\u003cp\u003eTesting methods/activities are limited exclusively to:\u003c/p\u003e\n\n\u003cp\u003e(1) Testing to detect a vulnerability or identify an indicator related to a vulnerability; or\u003cbr\u003e\n(2) Sharing information with, or receiving information from, EXIM about a vulnerability or an indicator related to a vulnerability.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eUnauthorized Testing Methods/Activities\u003c/h2\u003e\n\n\u003cp\u003eThe following test methods/activities are not authorized by EXIM:\u003c/p\u003e\n\n\u003cp\u003e• Test any systems other than the systems set forth in the ‘Scope’ of this policy.\u003cbr\u003e\n• Physical testing of facilities or resources (e.g., office access, open doors, tailgating).\u003cbr\u003e\n• Social engineering (e.g., phishing, vishing, spam, and other suspicious email), and any other non-technical vulnerability testing.\u003cbr\u003e\n• Network denial of service (DoS or Distributed DoS) or tests that impair access to or damage availability to a system or data.\u003cbr\u003e\n• Tests that exhausts bandwidth or are resource intensive.\u003cbr\u003e\n• Unidentified malware, viruses, Trojan horses, or worms.\u003cbr\u003e\n• Rainbow tables, password cracking, or brute force testing.\u003cbr\u003e\n• Use an exploit to exfiltrate data, establish command line access, establish a persistent presence on EXIM systems, or “pivot” to other EXIM systems.\u003cbr\u003e\n• Test third-party applications, websites, or services that integrate with or link to or from EXIM systems.\u003cbr\u003e\n• Delete, alter, share, retain, or destroy EXIM data, or render EXIM data inaccessible.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eQuestions\u003c/h2\u003e\n\n\u003cp\u003eQuestions or suggestions regarding this policy may be sent to VDP@exim.gov.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eThe Cybersecurity and Infrastructure Security Agency (CISA) Vulnerability Disclosure Policy Platform (VDP Platform) gives agencies the option to use a centrally managed system to intake vulnerability information from and collaborate with the public to improve the security of their internet-accessible systems. CISA has a contract with EnDyna and Bugcrowd, private companies, to manage the platform used by the public to report vulnerability information; CISA exercises general oversight of the program.  CISA does not collect, maintain, use, or disseminate any Personally Identifiable Information (PII) provided to Bugcrowd for the purposes of creating a profile on the website or reporting a vulnerability to agencies other than CISA.  Participating agencies provide their own program vulnerability disclosure policy, setting out the agency’s parameters for vulnerability disclosures, including provisions for collection and use of submitted information. Any submissions of vulnerabilities pertaining to CISA’s own information systems would be governed by the DHS VDP brief.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"c671c1c5-395a-409a-84e8-a2c48e059fab","name":"In Scope","targets":[{"id":"3de0022d-f814-47cc-94e0-b6a11fd10313","uri":"","name":"*.exim.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"3c330445-50ca-48fb-8005-9f40b6678da2","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eThis policy applies to anyone wishing to conduct vulnerability discovery activities, including research and testing conducted on EXIM’s publicly available systems/services within the EXIM.gov domain. This also includes the registered domain name EXIM.gov.\u003c/p\u003e\n\n\u003cp\u003eThough EXIM develops and maintains other internet-accessible systems or services, we ask that active research and testing be conducted only on the systems and services covered by the scope of this EXIM policy. We will increase the scope of this policy over time.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"7fd12e7d-b147-4eb6-8832-164bdb6d647f","code":"exim-vdp","state":"in_progress","endsAt":null,"bountyId":"2e67b5af-409f-4571-8c0d-7a45eb8662cc","startsAt":"2021-12-15T00:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Government","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/f3c6/9761/30dc05d8/1935450f8afe80abfef5669f375d27b9_8FOx9g9r_400x400.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2021-12-15T00:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/exim-vdp","changelogs":"/engagements/exim-vdp/changelog","submissions":null,"announcements":"/engagements/exim-vdp/announcements","hallOfFame":"/engagements/exim-vdp/hall_of_fames","crowdstream":"/engagements/exim-vdp/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/exim-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=exim-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/exim-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/exim-vdp/changelog","publishedAt":"2021-11-23T22:03:14.744Z","engagementChangelogUrl":"/engagements/exim-vdp/changelog/144e2dcb-9308-4884-8972-b2430779bf1e","createUserFeedbacksUrl":"/engagements/exim-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/exim-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}