{"id":"a4a6fc14-841a-4bb7-a18d-9f19e3e5c78f","engagementId":"db33eed6-d2af-4da1-94af-9c852ef9567d","data":{"brief":{"id":"ef8c46e4-837d-45dd-ada4-0d3d0afabc56","name":"Federal Deposit Insurance Corporation - Vulnerability Disclosure Program","tagline":"The Federal Deposit Insurance Corporation (FDIC) is an independent agency created to maintain stability and public confidence in the nation’s financial system.","description":"\u003ch1\u003eVulnerability Disclosure Policy\u003c/h1\u003e\n\n\u003cp\u003eThe Federal Deposit Insurance Corporation (“FDIC”) is committed to maintaining the security of our systems and protecting sensitive information from unauthorized disclosure.\u003c/p\u003e\n\n\u003cp\u003eWe encourage security researchers to report potential vulnerabilities identified in FDIC systems.  For reports submitted in compliance with this policy, the FDIC will endeavor to acknowledge receipt within three business days, to promptly validate submissions, implement corrective actions if appropriate, and inform researchers of the disposition of reported vulnerabilities.\u003c/p\u003e\n\n\u003cp\u003eIf you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized, we will work with you to understand and resolve the issue quickly, and we will not recommend or pursue legal action related to your research.\u003c/p\u003e","industryTagId":"2a38890b-c88e-4bc0-8db0-02059f3fafe6","targetsOverview":"\u003cp\u003eThis policy applies to all FDIC-managed systems and services that are accessible from the Internet. This includes systems and services on the registered domains names FDIC.gov, FDICCONNECT.gov, FDISOIG.gov, and OFIA.gov.  Vulnerabilities found in non-federal systems from our vendors fall outside of this policy’s scope and should be reported directly to the vendor according to its disclosure policy (if any).\u003c/p\u003e\n\n\u003ch2\u003eTest Methods\u003c/h2\u003e\n\n\u003cp\u003eSecurity researchers must not:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTest any system other than the systems set forth in the ‘Scope’ section;\u003c/li\u003e\n\u003cli\u003eDisclose vulnerability information except as set forth in the ‘Reporting a Vulnerability’ and ‘Disclosure’ sections;\u003c/li\u003e\n\u003cli\u003eEngage in physical testing of facilities or resources;\u003c/li\u003e\n\u003cli\u003eEngage in social engineering;\u003c/li\u003e\n\u003cli\u003eSend unsolicited electronic mail to FDIC users, including “phishing” messages;\u003c/li\u003e\n\u003cli\u003eExecute or attempt to execute “Denial of Service” or “Resource Exhaustion” attacks;\u003c/li\u003e\n\u003cli\u003eIntroduce malicious software;\u003c/li\u003e\n\u003cli\u003eTest in a manner which could degrade the operation of FDIC systems; or intentionally impair, disrupt, or disable FDIC systems;\u003c/li\u003e\n\u003cli\u003eTest third-party applications, websites, or services that integrate with or link to or from FDIC systems;\u003c/li\u003e\n\u003cli\u003eDelete data from or alter data on FDIC systems;\u003c/li\u003e\n\u003cli\u003eShare nonpublic FDIC data;\u003c/li\u003e\n\u003cli\u003eRetain FDIC data any longer than is necessary for authorized testing of FDIC systems or for documentation of the presence of a potential vulnerability;\u003c/li\u003e\n\u003cli\u003eDestroy or render FDIC data inaccessible;\u003c/li\u003e\n\u003cli\u003eDisclose any personally identifiable information discovered to any third party, or;\u003c/li\u003e\n\u003cli\u003eUse an exploit to exfiltrate data, establish command line access, establish a persistent presence on FDIC systems, or “pivot” to other FDIC systems.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eSecurity researchers may:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eView or store FDIC nonpublic data only to the extent necessary to document the presence of a potential vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eSecurity researchers must:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCease testing and notify us immediately upon discovery of a vulnerability.\u003c/li\u003e\n\u003cli\u003eCease testing and notify us immediately upon encountering nonpublic data.\u003c/li\u003e\n\u003cli\u003ePurge any stored FDIC nonpublic data upon reporting a vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eReporting a Vulnerability\u003c/h2\u003e\n\n\u003cp\u003eReports should provide a detailed technical description of the steps required to reproduce the vulnerability, including a description of any tools needed to identify or exploit the vulnerability.  Images, screen captures, and other documents may be attached to reports.  It is helpful to give attachments illustrative names.  Reports may include proof-of-concept code that demonstrates exploitation of the vulnerability.  \u003c/p\u003e\n\n\u003cp\u003eResearchers may submit reports anonymously.  Alternatively, researchers may provide contact information.  We may contact researchers to clarify reported vulnerability information or other technical interchange.\u003c/p\u003e\n\n\u003cp\u003eBy submitting a report to the FDIC, researchers warrant that the report and any attachments do not violate the intellectual property rights of any third party and the submitter grants the FDIC a non-exclusive, royalty-free, world-wide, perpetual license to use, reproduce, create derivative works, and publish the report and any attachments.\u003c/p\u003e\n\n\u003ch2\u003eDisclosure\u003c/h2\u003e\n\n\u003cp\u003eThe FDIC is committed to timely correction of vulnerabilities.  However, we recognize that public disclosure of a vulnerability in absence of a readily-available corrective action likely increases versus decreases risk.  If you believe others should be informed of the vulnerability prior to our implementation of corrective actions, we request that you coordinate in advance with us.\u003c/p\u003e\n\n\u003cp\u003eWe may share vulnerability reports with the Cybersecurity and Infrastructure Security Agency (CISA), as well as any affected vendors.  \u003c/p\u003e\n\n\u003ch2\u003ePrivacy Act Statement\u003c/h2\u003e\n\n\u003cp\u003eThe Federal Deposit Insurance Act (12 U.S.C. 1819) authorizes the collection of information by this system. FDIC collects the information in this system so that FDIC may correspond with individuals that voluntarily register and provide their contact information to FDIC via the Department of Homeland Security Cybersecurity and Infrastructure Security Agency’s crowd-sourced vulnerability disclosure policy platform. This information may be furnished to appropriate Federal, state, local or foreign authorities; to a court, administrative body, or a party in litigation; to contractors, agents and other third parties as authorized by law, or in accordance with any of the other routine uses described in the  FDIC Mailing, Event, and other Contact Lists System of Records, FDIC-040.  A complete copy of this System of Records is available at www.fdic.gov/about/privacy. Furnishing the requested information is voluntary. If you have questions or concerns about the collection or use of the information, you may contact the FDIC's Chief Privacy Officer at Privacy@fdic.gov.  \u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"210887e9-a09b-45e2-a493-ce74e54496d8","name":"In Scope","targets":[{"id":"c2e015b8-f743-4c16-90fd-4e51af76a9d3","uri":"https://www.fdic.gov/","name":"https://www.fdic.gov/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4fd59285-f933-4abf-9563-e26958fa95ca","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"c2e015b8-f743-4c16-90fd-4e51af76a9d3"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"c2e015b8-f743-4c16-90fd-4e51af76a9d3"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"c2e015b8-f743-4c16-90fd-4e51af76a9d3"}],"recentChangeFlags":null},{"id":"ea0fe06d-e00e-4701-b33e-82c610d5059b","uri":"https://www.fdicconnect.gov/index.asp","name":"https://www.fdicconnect.gov/index.asp","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ce34f2e6-540d-4459-bbd4-eaadb3016c29","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"ea0fe06d-e00e-4701-b33e-82c610d5059b"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"ea0fe06d-e00e-4701-b33e-82c610d5059b"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ea0fe06d-e00e-4701-b33e-82c610d5059b"}],"recentChangeFlags":null},{"id":"666ae47a-fa0f-4651-a4a2-16775e1d935a","uri":"https://fdicoig.gov/","name":"https://fdicoig.gov/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3022626e-ac88-4c05-bca0-c9ebdca1ef3c","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"666ae47a-fa0f-4651-a4a2-16775e1d935a"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"666ae47a-fa0f-4651-a4a2-16775e1d935a"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"666ae47a-fa0f-4651-a4a2-16775e1d935a"}],"recentChangeFlags":null},{"id":"324b3520-b560-4be1-b53f-97444a9989f3","uri":"https://www.ofia.gov/","name":"https://www.ofia.gov/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"64123aa0-df33-47ef-8e14-32ec6e618d36","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"324b3520-b560-4be1-b53f-97444a9989f3"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"324b3520-b560-4be1-b53f-97444a9989f3"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"324b3520-b560-4be1-b53f-97444a9989f3"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"db33eed6-d2af-4da1-94af-9c852ef9567d","code":"fdic-vdp","state":"in_progress","endsAt":null,"bountyId":"2adc41d5-d21e-4259-b10a-12c9be878040","startsAt":"2023-09-28T12:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Government","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/9457/22c2/8f1f838b/3b72d4eaa9b532f331fafdb8486dbf64_SEAL_BW.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2023-09-28T12:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/fdic-vdp","changelogs":"/engagements/fdic-vdp/changelog","submissions":null,"announcements":"/engagements/fdic-vdp/announcements","hallOfFame":"/engagements/fdic-vdp/hall_of_fames","crowdstream":"/engagements/fdic-vdp/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/fdic-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=fdic-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/fdic-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/fdic-vdp/changelog","publishedAt":"2023-06-01T01:47:39.025Z","engagementChangelogUrl":"/engagements/fdic-vdp/changelog/a4a6fc14-841a-4bb7-a18d-9f19e3e5c78f","createUserFeedbacksUrl":"/engagements/fdic-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/fdic-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}