{"id":"752d06eb-6302-4058-9ef2-5f17e2bf9b86","engagementId":"fd18ffa3-32e8-4e19-ad2e-d2f011d4948b","data":{"brief":{"id":"b8b841e0-c73e-403c-af22-1eef5ce4a879","name":"Figment Vulnerability Disclosure Program","tagline":"Serving customers worldwide, Figment is one of the world’s largest blockchain infrastructure and services provider.","description":"\u003cp\u003eFigment is the leading provider of staking infrastructure. Figment provides the complete staking solution for over 700 institutional clients, including asset managers, exchanges, wallets, foundations, custodians, and large token holders, to earn rewards on their digital assets. On Ethereum, Figment is the largest non-custodial staking provider of staked ETH. Institutional staking services from Figment include seamless point-and-click staking, portfolio reward tracking, API integrations, audited infrastructure, and slashing protection. This all leads Figment’s mission to support the adoption, growth, and long-term success of the digital asset ecosystem.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect and Figment believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities on our application. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. \u003cstrong\u003eAny domain/property of Figment not listed in the targets section is out of scope\u003c/strong\u003e. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Figment, you can report it to this program. However, be aware that it is ineligible for points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eProgram Requirements:\u003c/h2\u003e\n\n\u003cp\u003eAll BugCrowd users must use their \u003ccode\u003e[username]@bugcrowdninja.com\u003c/code\u003e email aliases for testing purposes.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e Any use of a personal email address will be considered as unauthorized and is out-of-scope for this program.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cp\u003e\u003ccode\u003efigment.io\u003c/code\u003e is a public facing corporate website running on Wordpress.\u003cbr\u003e\n\u003ccode\u003eapp.figment.io\u003c/code\u003e is a public facing web application.\u003cbr\u003e\n\u003ccode\u003eapi.figment.io\u003c/code\u003e is a public facing API for our applications.\u003cbr\u003e\n\u003ccode\u003edapp.figment.io\u003c/code\u003e is a staking widget intended to be integrated into specific platforms.\u003cbr\u003e\n\u003ccode\u003erewards-calculator.figment.io\u003c/code\u003e is a rewards calculator intended to be integrated into \u003ccode\u003eapp.figment.io\u003c/code\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eSelf-XSS that cannot be used to exploit other users\u003c/li\u003e\n\u003cli\u003eVerbose messages/files/directory listings without disclosing any sensitive information\u003c/li\u003e\n\u003cli\u003eCORS mis-configuration on non sensitive end points\u003c/li\u003e\n\u003cli\u003eMissing cookie flags on non-sensitive cookies\u003c/li\u003e\n\u003cli\u003eMissing security headers which do not present an immediate security vulnerability\u003c/li\u003e\n\u003cli\u003eCross-site Request Forgery with no or low impact\u003c/li\u003e\n\u003cli\u003ePresence of autocomplete attribute on web forms\u003c/li\u003e\n\u003cli\u003eTab nabbing and reverse tab nabbing\u003c/li\u003e\n\u003cli\u003eBypassing rate-limits or the non-existence of rate-limits\u003c/li\u003e\n\u003cli\u003eBest practices violations (password complexity, expiration, re-use, etc.)\u003c/li\u003e\n\u003cli\u003eClickjacking on pages without sensitive actions\u003c/li\u003e\n\u003cli\u003eHost Header Injection\u003c/li\u003e\n\u003cli\u003eCross-domain referer leakage\u003c/li\u003e\n\u003cli\u003eContent injection that cannot be used to exploit other users\u003c/li\u003e\n\u003cli\u003eHTTP Request smuggling without any proven impact\u003c/li\u003e\n\u003cli\u003eHomograph attacks\u003c/li\u003e\n\u003cli\u003eXMLRPC enabled\u003c/li\u003e\n\u003cli\u003eBanner grabbing / Version disclosure\u003c/li\u003e\n\u003cli\u003eOpen ports without an accompanying proof-of-concept demonstrating vulnerability\u003c/li\u003e\n\u003cli\u003eWeak SSL configurations and SSL/TLS scan reports\u003c/li\u003e\n\u003cli\u003eNot stripping metadata of images\u003c/li\u003e\n\u003cli\u003eArbitrary file upload without proof of the existence of the uploaded file\u003c/li\u003e\n\u003cli\u003eCrashes due to malformed URL Schemes\u003c/li\u003e\n\u003cli\u003eVulnerabilities that are limited to non-current browsers (older than 3 versions) will not be accepted\u003c/li\u003e\n\u003cli\u003eAttacks requiring unrealistic user interaction\u003c/li\u003e\n\u003cli\u003eSpam, social engineering and physical intrusion\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"011c4616-9146-47ac-bf46-c247c4def7c3","name":"In Scope Targets ","targets":[{"id":"f1a081ca-a119-42f3-858d-3f8ecfaa5a44","uri":"https://figment.io","name":"figment.io","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"81c5d718-3c85-46cf-8c96-3813452f5930","sortOrder":0},"sortOrder":0,"tags":[{"id":"487e9af0-2610-4813-a092-ea46f4cb6de1","name":"Wordpress","targetId":"f1a081ca-a119-42f3-858d-3f8ecfaa5a44"}],"recentChangeFlags":null},{"id":"3ed31b37-1971-4a6d-bbd3-7806980940d8","uri":"https://app.figment.io","name":"app.figment.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"92313fc4-6ec7-453d-b159-d8d884f0a20e","sortOrder":1},"sortOrder":1,"tags":[{"id":"624f911d-7e8c-4d56-b523-e7416c1cc319","name":"NextJS","targetId":"3ed31b37-1971-4a6d-bbd3-7806980940d8"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"3ed31b37-1971-4a6d-bbd3-7806980940d8"}],"recentChangeFlags":null},{"id":"c29feaaa-7e6b-40d7-9491-48cda4c255e1","uri":"https://api.figment.io","name":"api.figment.io ","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2ef83c43-067d-488d-9fca-6376a8c0f52a","sortOrder":2},"sortOrder":2,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"c29feaaa-7e6b-40d7-9491-48cda4c255e1"},{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"c29feaaa-7e6b-40d7-9491-48cda4c255e1"}],"recentChangeFlags":null},{"id":"6651de8f-f7a9-4e2e-9b49-9a1fe4d0b45f","uri":"https://dapp.figment.io","name":"dapp.figment.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"353e55fa-f8e2-456b-8331-d3a9f6eb1411","sortOrder":3},"sortOrder":3,"tags":[{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"6651de8f-f7a9-4e2e-9b49-9a1fe4d0b45f"}],"recentChangeFlags":null},{"id":"767c6bef-78c4-4cb3-bf88-50f6a5f3dbd0","uri":"https://rewards-calculator.figment.io","name":"rewards-calculator.figment.io","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"cd312a75-1311-490a-be11-4655393f2b9c","sortOrder":4},"sortOrder":4,"tags":[{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"767c6bef-78c4-4cb3-bf88-50f6a5f3dbd0"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch1\u003eRules of Engagement\u003c/h1\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRequired:\u003c/strong\u003e Must use \u003cstrong\u003e[username]@bugcrowdninja.com\u003c/strong\u003e email alias for any user account testing activity.\u003c/li\u003e\n\u003cli\u003ePlease clean up remnants of your testing and do not interfere with the normal operation of the site.\u003c/li\u003e\n\u003cli\u003ePlease do NOT use automatic scanners. We will NOT accept any submissions found by using automatic scanners.\u003c/li\u003e\n\u003cli\u003eProvide detailed but to-the-point reproduction steps.\u003c/li\u003e\n\u003cli\u003eInclude a clear attack scenario.\u003c/li\u003e\n\u003cli\u003eRecommendations for mitigation are appreciated.\u003c/li\u003e\n\u003cli\u003eDo not exploit the identified leak: only collect the information necessary to demonstrate its existence.\u003c/li\u003e\n\u003cli\u003eDo not change or delete any data or system settings.\u003c/li\u003e\n\u003cli\u003eHandle any found data in a responsible manner: if you can demonstrate that there is a security problem with a small portion, do not go any further.\u003c/li\u003e\n\u003cli\u003eRemember: quality over quantity!\u003c/li\u003e\n\u003cli\u003eYou must be at least 18 years of age; if you are considered a minor where you live, you must have your parent’s or legal guardian’s permission prior to submitting a vulnerability.\u003c/li\u003e\n\u003cli\u003eOnly engage in vulnerability testing within the scope of this program.\u003c/li\u003e\n\u003cli\u003eDo not engage in any activity that can potentially or actually cause harm to Figment, our customers, or our employees.\u003c/li\u003e\n\u003cli\u003eDo not engage in any activity that can potentially or actually stop or degrade Figment’s services or assets.\u003c/li\u003e\n\u003cli\u003eDo not engage in any activity that violates any applicable federal, provincial/state and/or local laws or regulations in connection with your security research activities or other participation in this vulnerability disclosure program.\u003c/li\u003e\n\u003cli\u003eDo not disclose information related to your findings to any third party or the public without Figment’s prior written consent in each instance.\u003c/li\u003e\n\u003cli\u003eAny and all information acquired or accessed by you as part of this exercise is confidential\u003c/li\u003e\n\u003cli\u003eFigment and you shall hold the confidential information in strict confidence and shall not copy, reproduce, sell, assign, licence, market, transfer or otherwise dispose of, give or disclose such information to third parties or use such information for any purposes other than for the performance of your work.\u003c/li\u003e\n\u003cli\u003eDo not store, share, compromise or destroy Figment or customer data. If Personally Identifiable Information (PII) is encountered, you should immediately halt your activity, purge related data from your system, and immediately contact Figment.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eFigment will not pursue legal action against you as long as you submit your findings in accordance with the above rules. Figment reserves all legal rights in the event of noncompliance with these rules.\u003c/p\u003e\n\n\u003cp\u003eData exfiltration, continued exploitation, and public disclosure prior to Figment review shall be considered malicious, unauthorised activity, and, in such instances, Figment will pursue legal action against you, including reporting such activity to law enforcement agencies.\u003c/p\u003e\n\n\u003cp\u003eBy submitting a report, you are indicating that you have read, understand, and agree to the above requirements.\u003c/p\u003e\n\n\u003cp\u003eThank you,\u003c/p\u003e\n\n\u003cp\u003eFigment Security.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"fd18ffa3-32e8-4e19-ad2e-d2f011d4948b","code":"figment-vdp","state":"in_progress","endsAt":null,"bountyId":"17380e5d-6877-4cb9-a6a8-6927a0fa20a8","startsAt":"2022-04-28T19:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/135f/f463/ac3393f3/8b6e0fefa030b1be5e7ef93f6655fad5_1565222515006.jpeg","logoBackgroundColor":"#000000","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2022-04-28T19:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/figment-vdp","changelogs":"/engagements/figment-vdp/changelog","submissions":null,"announcements":"/engagements/figment-vdp/announcements","hallOfFame":"/engagements/figment-vdp/hall_of_fames","crowdstream":"/engagements/figment-vdp/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/figment-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=figment-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/figment-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/figment-vdp/changelog","publishedAt":"2025-03-26T17:40:43.953Z","engagementChangelogUrl":"/engagements/figment-vdp/changelog/752d06eb-6302-4058-9ef2-5f17e2bf9b86","createUserFeedbacksUrl":"/engagements/figment-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/figment-vdp/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}