{"id":"f090483f-bf37-440c-9de4-e448146e5e7d","engagementId":"d1b36c22-180c-42da-a8d2-dfc1541ef8a1","data":{"brief":{"id":"f1e24058-aa55-4ac8-8d03-b495f9cd77fb","name":"55 Degrees","tagline":"Test your skills on 55 Degrees's program!","description":"\u003cp\u003e\u003cstrong\u003eThis bounty is part of the Atlassian Marketplace Bounty Program\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e55 Degrees helps companies get more done with less stress. We do this by offering training and consultancy within the Lean and Agile space. In addition, we build apps that help our customers get their jobs done. \u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eOnly test \u003ca href=\"https://marketplace.atlassian.com/apps/1216661/actionableagile-for-jira-agile-metrics\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eActionableAgile for Jira\u003c/a\u003e. No other versions of ActionableAgile are in scope or part of this program.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch4\u003eGet Started (tl;dr version)\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eDo not access, impact, destroy or otherwise negatively impact 55 Degrees or Atlassian customers, or customer data in any way.\u003c/li\u003e\n\u003cli\u003eEnsure that you use your \u003cem\u003e@bugcrowdninja.com\u003c/em\u003e email address.\u003c/li\u003e\n\u003cli\u003eEnsure you understand the targets, scopes, exclusions, and rules below.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eQuick Links\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://marketplace.atlassian.com/apps/1216661/actionableagile-for-jira-agile-metrics\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eActionableAgile for Jira\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cp\u003eBelow is a list of some of the vulnerability classes that we are seeking reports for:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCross Instance Data Leakage/Access**\u003c/li\u003e\n\u003cli\u003eServer-side Remote Code Execution (RCE)\u003c/li\u003e\n\u003cli\u003eServer-Side Request Forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eStored/Reflected Cross-site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eCross-site Request Forgery (CSRF)\u003c/li\u003e\n\u003cli\u003eSQL Injection (SQLi)\u003c/li\u003e\n\u003cli\u003eXML External Entity Attacks (XXE)\u003c/li\u003e\n\u003cli\u003eAccess Control Vulnerabilities (Insecure Direct Object Reference issues, etc)\u003c/li\u003e\n\u003cli\u003ePath/Directory Traversal Issues\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e** Cross Instance Data Leakage/Access refers to unauthorized data access between instances. \u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eEnsure you review the out of scope and exclusions list for further details.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":null,"targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as In-Scope. \u003cem\u003eAny domain/property of 55 Degrees  not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/em\u003e If you believe you've identified a vulnerability on a system outside the scope, please reach out to support@bugcrowd.com before submitting.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCreating Your Instance\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eJIRA + Confluence Cloud\u003c/strong\u003e\u003cbr\u003e\nTo access the instance and start your testing (after you've read and understood the scope and exclusions listed below, of course) you can follow the below steps:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNavigate to the checkout page \u003ca href=\"https://www.atlassian.com/ondemand/signup/form?product=confluence.ondemand,jira-software.ondemand,jira-servicedesk.ondemand\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eClick \"Next\"\u003c/li\u003e\n\u003cli\u003eComplete the form, using the following format: \u003cstrong\u003ebugbounty-test-\u0026lt;bugcrowd-name\u0026gt;\u003c/strong\u003e\nNote that \u0026lt;bugcrowd-name\u0026gt; should be replaced with your own Bugcrowd username \u003c/li\u003e\n\u003cli\u003eClick \"Start now\"\u003c/li\u003e\n\u003cli\u003eOnce your instance has been completed that's it - you can test away.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eCross Instance Data Leakage/Access**\u003c/li\u003e\n\u003cli\u003eServer-side Remote Code Execution (RCE)\u003c/li\u003e\n\u003cli\u003eServer-Side Request Forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eStored/Reflected Cross-site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eCross-site Request Forgery (CSRF)\u003c/li\u003e\n\u003cli\u003eSQL Injection (SQLi)\u003c/li\u003e\n\u003cli\u003eXML External Entity Attacks (XXE)\u003c/li\u003e\n\u003cli\u003eAccess Control Vulnerabilities (Insecure Direct Object Reference issues, etc)\u003c/li\u003e\n\u003cli\u003ePath/Directory Traversal Issues\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e** Cross Instance Data Leakage/Access refers to unauthorized data access between instances. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cp\u003eFor the Server and Data Center distribution versions - we only accept vulnerabilities affecting the latest version of the installed product. If a vulnerability is found for one distribution, you cannot submit the vulnerability for the other distributions (ie. if you find it on the Server version, you cannot submit it for Cloud or Data Center - no double dipping).\u003c/p\u003e\n\n\u003cp\u003eActionableAgile for Jira embeds the Portfolio Forecaster app within it (the page will be labeled \"Portfolio Forecaster\"). If you find a vulnerability for Portfolio Forecaster, you cannot submit the vulnerability for the embedded Portfolio Forecaster in ActionableAgile for Jira as well (no double-dipping between the apps).\u003c/p\u003e\n\n\u003cp\u003eActionableAgile for Jira uses the browser’s localStorage mechanism for storing data. Any vulnerabilities related to localStorage or the data stored in localStorage is out of scope. \u003c/p\u003e\n\n\u003cp\u003eNote: No other versions of ActionableAgile are in scope. Only the ActionableAgile for Jira available on the Atlassian Marketplace is in scope. \u003c/p\u003e\n\n\u003cp\u003eAny platform bugs on partner's forge apps must be reported to Atlassian.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eBlind XSS must not return any user data that you do not have access to (e.g. Screen shots, cookies that aren't owned by you, etc); when testing for blind XSS, please use the least invasive test possible (e.g. calling 1x1 image or nonexistent page on your webserver, etc).\u003c/li\u003e\n\u003cli\u003eWhen testing, please exercise caution if injecting on any form that may be publicly visible - such as forums, etc. Before injection, please make sure your payload can be removed from the site. If it cannot be easily removed, please check with support@bugcrowd before performing the testing.\u003c/li\u003e\n\u003cli\u003eNo pivoting or post exploitation attacks (i.e. using a vulnerability to find another vulnerability) are allowed on this program. DO NOT under any circumstance leverage a finding to identify further issues.\u003c/li\u003e\n\u003cli\u003eAny 55 Degrees website or application is out of scope for this bounty unless it is directly accessible from one of the targets or any associated services attached to the instance.\u003c/li\u003e\n\u003cli\u003eCustomer cloud instances and data are explicitly out of scope.\u003c/li\u003e\n\u003cli\u003eAny repository that you are not an owner of - do not impact 55 Degrees, or Atlassian customers in any way.\u003c/li\u003e\n\u003cli\u003eOnly the latest version of our products are eligible for a reward.\u003c/li\u003e\n\u003cli\u003eAny internal or development services\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eThe following finding types are specifically excluded from the bounty\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eLack of Rate Limiting on any of the targets.\u003c/li\u003e\n\u003cli\u003eThe use of Automated scanners is strictly prohibited (we have these tools too - don't even think about using them)\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g. Stack Traces, application or server errors).\u003c/li\u003e\n\u003cli\u003eFingerprinting / banner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eLogout Cross-Site Request Forgery (logout CSRF).\u003c/li\u003e\n\u003cli\u003eContent Spoofing.\u003c/li\u003e\n\u003cli\u003ePresence of application or web browser ‘autocomplete’ or ‘save password’ functionality.\u003c/li\u003e\n\u003cli\u003eLack of Secure/HTTPOnly flags on non-sensitive Cookies.\u003c/li\u003e\n\u003cli\u003eLack of Security Speedbump when leaving the site.\u003c/li\u003e\n\u003cli\u003eWeak Captcha / Captcha Bypass.\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force and account lockout not enforced.\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration.\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers, specifically (\u003ca href=\"https://owasp.org/www-project-secure-headers/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://owasp.org/www-project-secure-headers/\u003c/a\u003e), e.g.\n\n\u003cul\u003e\n\u003cli\u003eStrict-Transport-Security.\u003c/li\u003e\n\u003cli\u003eX-Frame-Options.\u003c/li\u003e\n\u003cli\u003eX-XSS-Protection.\u003c/li\u003e\n\u003cli\u003eX-Content-Type-Options.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy, X-Content-Security-Policy, X-WebKit-CSP.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy-Report-Only.\u003c/li\u003e\n\u003cli\u003eCache-Control and Pragma\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eHTTP/DNS cache poisoning.\u003c/li\u003e\n\u003cli\u003eSSL/TLS Issues, e.g.\n\n\u003cul\u003e\n\u003cli\u003eSSL Attacks such as BEAST, BREACH, Renegotiation attack.\u003c/li\u003e\n\u003cli\u003eSSL Forward secrecy not enabled.\u003c/li\u003e\n\u003cli\u003eSSL weak/insecure cipher suites.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSelf-XSS reports will not be accepted.\n\n\u003cul\u003e\n\u003cli\u003eSimilarly, any XSS where local access is required (i.e. User-Agent Header injection) will not be accepted. The only exception will be if you can show a working off-path MiTM attack that will allow for the XSS to trigger.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerabilities that are limited to unsupported browsers will not be accepted (i.e. \"this exploit only works in IE6/IE7\"). A list of supported browsers can be found \u003ca href=\"https://confluence.atlassian.com/display/Cloud/Supported+browsers\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eKnown vulnerabilities in used libraries, or the reports that an Atlassian product uses an outdated third party library (e.g. jQuery, Apache HttpComponents etc) unless you can prove exploitability.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect SPF records of any kind.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect DMARC records of any kind.\u003c/li\u003e\n\u003cli\u003eSource code disclosure vulnerabilities.\u003c/li\u003e\n\u003cli\u003eInformation disclosure of non-confidential information (e. g. issue id, project id, commit hashes).\u003c/li\u003e\n\u003cli\u003eThe ability to upload/download viruses or malicious files to the platform.\u003c/li\u003e\n\u003cli\u003eEmail bombing/Flooding/rate limiting.\u003c/li\u003e\n\u003cli\u003eJWT in ajax requests ignores path and HTTP method.\u003c/li\u003e\n\u003cli\u003eFor some of our apps, we allow arbitrary HTML templates to be defined by administrators. Those could potentially be used for XSS attacks, however since only administrators have access we don't consider those as security threats.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003ePublic Disclosure\u003c/h3\u003e\n\n\u003cp\u003eBefore disclosing an issue publicly we require that you first request permission from us.\u003cbr\u003e\n55 Degrees will process requests for public disclosure on a per report basis. Requests to publicly disclose an issue that has not yet been fixed for customers will be rejected. Any researcher found publicly disclosing reported vulnerabilities without 55 Degrees's written consent will have any allocated bounty withdrawn and disqualified from the program.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"b4e613a6-6983-42ff-ad42-8785da8c0847","name":"In Scope","targets":[{"id":"a90b3c6c-5c42-4874-b78c-99daacedb399","uri":"https://marketplace.atlassian.com/apps/1216661/actionableagile-for-jira-agile-metrics?hosting=cloud\u0026tab=overview","name":"https://marketplace.atlassian.com/apps/1216661/actionableagile-for-jira-agile-metrics?hosting=cloud\u0026tab=overview","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d5cf3ebc-0503-43a6-9256-c98ef6b05001","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a90b3c6c-5c42-4874-b78c-99daacedb399"}],"recentChangeFlags":null},{"id":"f9e54f9b-13c8-471b-89eb-935906280699","uri":"https://marketplace.atlassian.com/apps/1216661/actionableagile-for-jira-agile-metrics?hosting=server\u0026tab=overview","name":"https://marketplace.atlassian.com/apps/1216661/actionableagile-for-jira-agile-metrics?hosting=server\u0026tab=overview","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f0687b14-9e97-4e60-940e-bf053591a9a8","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f9e54f9b-13c8-471b-89eb-935906280699"}],"recentChangeFlags":null},{"id":"cfef6b26-e170-47ef-b610-bb7eb1475a2d","uri":"https://marketplace.atlassian.com/apps/1216661/actionableagile-for-jira-agile-metrics?hosting=datacenter\u0026tab=overview","name":"https://marketplace.atlassian.com/apps/1216661/actionableagile-for-jira-agile-metrics?hosting=datacenter\u0026tab=overview","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c1788202-a2ba-4956-9fcc-217837e4988d","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"cfef6b26-e170-47ef-b610-bb7eb1475a2d"}],"recentChangeFlags":null},{"id":"a7821260-f0b2-4d66-9c0a-cd9e39844975","uri":null,"name":"Anything related to the actionableagile.55degrees-apps.net subdomain is in scope. ","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6900d598-b3ac-4bff-94fe-8a2795914b1c","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a7821260-f0b2-4d66-9c0a-cd9e39844975"}],"recentChangeFlags":null},{"id":"b94946ae-aa39-4ea8-b31b-0f3df5760129","uri":"https://marketplace.atlassian.com/apps/1216661/actionableagile-for-jira-agile-metrics?hosting=cloud","name":"https://marketplace.atlassian.com/apps/1216661/actionableagile-for-jira-agile-metrics?hosting=cloud","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"9a92c938-1231-4f0d-8f84-c77dae0c6192","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b94946ae-aa39-4ea8-b31b-0f3df5760129"}],"recentChangeFlags":null},{"id":"a4a5dcc8-3e43-4289-9200-59eccf183c9c","uri":"https://marketplace.atlassian.com/apps/1216661/actionableagile-for-jira-agile-metrics?hosting=server","name":"https://marketplace.atlassian.com/apps/1216661/actionableagile-for-jira-agile-metrics?hosting=server","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"eed2fee0-6f33-45a6-9f2c-27cf7377ec8d","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a4a5dcc8-3e43-4289-9200-59eccf183c9c"}],"recentChangeFlags":null},{"id":"ba580fa1-f4c2-43e1-8f60-105caa4ca9de","uri":"https://marketplace.atlassian.com/apps/1216661/actionableagile-for-jira-agile-metrics?hosting=datacenter","name":"https://marketplace.atlassian.com/apps/1216661/actionableagile-for-jira-agile-metrics?hosting=datacenter","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"71617ca6-b4a5-4b36-89fb-9c903ca21211","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ba580fa1-f4c2-43e1-8f60-105caa4ca9de"}],"recentChangeFlags":null},{"id":"3e3d942e-11e3-4e09-b58a-c1b166d5db81","uri":"https://marketplace.atlassian.com/apps/1220160/issue-analyzer-for-jira?hosting=cloud\u0026tab=overview","name":"https://marketplace.atlassian.com/apps/1220160/issue-analyzer-for-jira?hosting=cloud\u0026tab=overview","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"065e2c90-8d0a-4187-a6b7-fd558f8c04d7","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"3e3d942e-11e3-4e09-b58a-c1b166d5db81"}],"recentChangeFlags":null},{"id":"db456014-f66e-4007-b66b-9d7d26b3e55e","uri":"https://marketplace.atlassian.com/apps/1224766/portfolio-forecaster?hosting=cloud\u0026tab=overview","name":"https://marketplace.atlassian.com/apps/1224766/portfolio-forecaster?hosting=cloud\u0026tab=overview","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"796257f8-2b37-4eed-ba2a-91d34bc53428","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"db456014-f66e-4007-b66b-9d7d26b3e55e"}],"recentChangeFlags":null},{"id":"6ac56cd6-d38d-47ce-83a3-6e88cb58f2c0","uri":"https://marketplace.atlassian.com/apps/1224766/portfolio-forecaster?hosting=datacenter\u0026tab=overview","name":"https://marketplace.atlassian.com/apps/1224766/portfolio-forecaster?hosting=datacenter\u0026tab=overview","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"84fec94c-bf9c-4017-9d48-3ff52b523071","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"6ac56cd6-d38d-47ce-83a3-6e88cb58f2c0"}],"recentChangeFlags":null},{"id":"8a1cf8f6-0198-4884-91f4-1310567531f4","uri":"https://marketplace.atlassian.com/apps/1227773/klar-issue-refinement-for-jira?hosting=cloud\u0026tab=overview","name":"https://marketplace.atlassian.com/apps/1227773/klar-issue-refinement-for-jira?hosting=cloud\u0026tab=overview","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"9b9a8f2e-231c-42a3-84c6-d1bb74be2185","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"8a1cf8f6-0198-4884-91f4-1310567531f4"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"c834570f-26c6-44e1-9bba-5edeaba825fa","p1MaxCents":150000,"p1MinCents":150000,"p2MaxCents":90000,"p2MinCents":90000,"p3MaxCents":30000,"p3MinCents":30000,"p4MaxCents":10000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":1500,"max":1500},"2":{"min":900,"max":900},"3":{"min":300,"max":300},"4":{"min":100,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"a8083dd9-c83c-455c-86cd-28dcf6821e95","name":"Out of scope","targets":[{"id":"6a29c363-bdad-4718-ba68-4650e5c90c50","uri":null,"name":"Any other subdomains on 55degrees-apps.net or any other domains owned by 55 Degrees AB is out of scope. ","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b6772a47-bab3-4557-9eac-f262aa4a9c7a","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"6a29c363-bdad-4718-ba68-4650e5c90c50"}],"recentChangeFlags":null},{"id":"3f727dbb-dfdc-4d97-8cd5-4bb0e5a077a7","uri":null,"name":"https://marketplace.atlassian.com/*","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ba3cf881-724e-4a8a-aaaf-b1878396cae2","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"d1b36c22-180c-42da-a8d2-dfc1541ef8a1","code":"fiftyfivedegrees","state":"in_progress","endsAt":null,"bountyId":"45468bf5-b61a-43b0-8be7-cf8f124b0839","startsAt":"2020-07-07T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":null,"methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/354f/0577/20e00506/0e575127ca301936d222992eb4985b6a_55degrees.png","logoBackgroundColor":"#FFFFFF","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2020-07-07T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/fiftyfivedegrees","changelogs":"/engagements/fiftyfivedegrees/changelog","submissions":null,"announcements":"/engagements/fiftyfivedegrees/announcements","hallOfFame":"/engagements/fiftyfivedegrees/hall_of_fames","crowdstream":"/engagements/fiftyfivedegrees/crowdstream"},"announcementsCount":3,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/fiftyfivedegrees/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=fiftyfivedegrees\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/fiftyfivedegrees/engagement_subscribers","engagementChangelogsUrl":"/engagements/fiftyfivedegrees/changelog","publishedAt":"2026-07-08T20:13:41.061Z","engagementChangelogUrl":"/engagements/fiftyfivedegrees/changelog/f090483f-bf37-440c-9de4-e448146e5e7d","createUserFeedbacksUrl":"/engagements/fiftyfivedegrees/feedbacks","engagementCrowdstreamUrl":"/engagements/fiftyfivedegrees/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}