{"id":"b69ed633-de6a-40f8-9636-86b963afa267","engagementId":"c6fa610f-d256-4794-abd2-3737a862c22d","data":{"brief":{"id":"8e8245c2-b1d2-4886-9d74-f8303dcd31b1","name":"Certinia (formerly FinancialForce)","tagline":"Certinia gives you a complete, customer-centric view of your business on the world's #1 cloud platform from Salesforce","description":"\u003cp\u003eNo technology is perfect and Certinia believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our web applications. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eOur team cares deeply about security, and we recognize that community-driven security research is the best way to help us keep us and our customers secure.\u003c/p\u003e\n\n\u003cp\u003eIf you have found a vulnerability in our systems, please follow the guidelines below and send it our way.\u003c/p\u003e\n\n\u003cp\u003eHappy hunting!\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as In-Scope. Any domain/property of Certinia not listed in the targets section is out of scope. This includes any/all subdomains not listed above. IF you happen to identify a security vulnerability on a target that is not in-scope, but that demonstrably belongs to Certinia, it may be reported to this program, and is appreciated - but will ultimately be marked as ‘not applicable’ and will not be eligible for monetary or points-based compensation.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003ePlease read the focus areas and out-of-scope items carefully to avoid your submission from being marked as out of scope, as this may make you lose points.\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthentication bypass (e.g., token theft, SSO misconfiguration, etc.)\u003c/li\u003e\n\u003cli\u003eRCE (Remote code execution)\u003c/li\u003e\n\u003cli\u003eXSS (Cross-Site-Scripting)\u003c/li\u003e\n\u003cli\u003eXXE (XML External Entity injection)\u003c/li\u003e\n\u003cli\u003eSQLi (SQL injection).\u003c/li\u003e\n\u003cli\u003eOpen redirect.\u003c/li\u003e\n\u003cli\u003eSSRF (Server-Side Request Forgery)\u003c/li\u003e\n\u003cli\u003eDisclosure of sensitive information such as credentials or PII.\u003c/li\u003e\n\u003cli\u003eCSRF or Clickjacking where credentials can be exfiltrated or sensitive operations can be performed (excluding login/logout)\u003c/li\u003e\n\u003cli\u003eDMARC/SPF bypass with a working PoC, but only if:\n\n\u003cul\u003e\n\u003cli\u003eThe issue is due to a misconfiguration on our end which can be fixed.\u003c/li\u003e\n\u003cli\u003eYou have only sent emails on behalf of hackers@certinia.com.\u003c/li\u003e\n\u003cli\u003eYou have only sent emails to the spoof@certinia.com inbox.\u003c/li\u003e\n\u003cli\u003eYou do not send additional exploits, tracking pixels, etc. in your email.\u003c/li\u003e\n\u003cli\u003eYou provide a long, unique string in your email subject (not the body), and mention this in your report so we can verify.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSubdomain takeovers:\n\n\u003cul\u003e\n\u003cli\u003eMust be reported within 72hrs of the takeover\u003c/li\u003e\n\u003cli\u003eDemo pages must be static and innocuous, and not hosted on the root domain (e.g., host on /takeover_poc_by_\u0026lt;alias\u0026gt; or similar)\u003c/li\u003e\n\u003cli\u003eWe recommend either holding on to the takeover or taking a snapshot in Wayback Machine as proof\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAny other security issue with a verifiable vulnerability and tangible impact.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eReports against *.salesforce.com or related Salesforce domains.\u003c/li\u003e\n\u003cli\u003ePDFs under https://certinia.com that contain the string \"Confidential\". These files are intended to be public.\u003c/li\u003e\n\u003cli\u003eExposing \"Server\" HTTP header, stack traces, verbose errors, etc. without demonstrable impact\u003c/li\u003e\n\u003cli\u003eTheoretical issues without demonstrating exploitability (e.g., security headers, CVEs, outdated third-party libraries, etc.).\u003c/li\u003e\n\u003cli\u003eCORS misconfiguration issues unless chained with another vulnerability\u003c/li\u003e\n\u003cli\u003eDenial of Service, \u003cstrong\u003ebrute force attacks\u003c/strong\u003e, lack of rate limiting, or reporting issues that depend on these techniques.\u003c/li\u003e\n\u003cli\u003eAutomated scan results without providing evidence that the issue can be exploited.\u003c/li\u003e\n\u003cli\u003eSelf-XSS.\u003c/li\u003e\n\u003cli\u003eSSL certificate or DNS configuration issues without demonstrating impact and providing a PoC.\u003c/li\u003e\n\u003cli\u003eClickjacking on pages with no sensitive actions.\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eUnauthenticated/logout/login CSRF.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMan-In-The-Middle attacks, or vulnerabilities that depend on it.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAny physical attacks on Certinia property or personnel.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIssues requiring access to a victim's device.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSocial engineering attacks (e.g., phishing, smishing, vishing, etc.).\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eCVEs or other security advisory issues without corresponding patches.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIssues with corresponding patches that are younger than 60 days.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e0-day vulnerabilities less than 90 days from patch release.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eVulnerabilities affecting only outdated or misconfigured browsers.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eEligibility\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou must not be a resident of, or make your Submission from, a country against which the United States has issued export sanctions or other trade restrictions (e.g., Cuba, Iran, North Korea, Sudan and Syria, countries in OFAC-sanctioned list, etc.)\u003c/li\u003e\n\u003cli\u003eBe in violation of any national, state, or local law or regulation\u003c/li\u003e\n\u003cli\u003eYou must be the first one to report the issue. We will also not reward you for a vulnerability we are already aware of.\u003c/li\u003e\n\u003cli\u003eYou must have personally discovered the vulnerability.\u003c/li\u003e\n\u003cli\u003eYou must not be employed by Certinia or any related entities, currently or in the last year.\u003c/li\u003e\n\u003cli\u003eYou must comply with this Policy when discovering the vulnerability and submitting the vulnerability report.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eWriting your report\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eReports must be provided in English (don't worry if it's not perfect English).\u003c/li\u003e\n\u003cli\u003eProvide a working PoC with clear steps to reproduce the issue. We will automatically reject any theoretical or speculative issues.\u003c/li\u003e\n\u003cli\u003eProvide your assessment of the impact of the issue, but avoid bloating issues with theoretical impact.\u003c/li\u003e\n\u003cli\u003eAvoid reporting multiple issues in the same report, unless they are part of the same attack chain.\u003c/li\u003e\n\u003cli\u003eIf a single issue affects multiple systems, please raise a single, consolidated report as opposed to having a separate report for each system.\u003c/li\u003e\n\u003cli\u003eIf any of the above are not satisfactorily met, Certinia have the right to disqualify your submission, but may still reference what has been submitted for our further consideration.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eResponsible Disclosure\u003c/h3\u003e\n\n\u003cp\u003eWe believe in responsible disclosure, so we ask that you:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePlay nice. Signs of blackmail, bribery, extortion, fraudulent activity, coercion, threats, or offensive language will not be tolerated.\u003c/li\u003e\n\u003cli\u003eAvoid drip-feeding issues. For example, if you find the same vulnerability affects multiple systems, please write a combined report for all of them.\u003c/li\u003e\n\u003cli\u003eReport issues as soon as possible via the Bugcrowd program.\u003c/li\u003e\n\u003cli\u003eDo not publish any details of your findings until we have had a reasonable amount of time to release fixes for them.\u003c/li\u003e\n\u003cli\u003eNotify us before you publish anything.\u003c/li\u003e\n\u003cli\u003eAvoid accessing or modifying any sensitive information. In the event you do any of this inadvertently, contact us immediately at security@certinia.com providing details on what data was affected, how and when you accessed the data, and all relevant technical details. Don't worry about assessing the impact in this scenario, just report the incident ASAP.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eGrounds for disqualification\u003c/h3\u003e\n\n\u003cp\u003eWe love a good attack chain, but we also like keeping our systems up and running, keeping our employees happy and productive, and being able to sleep at night. By doing any of the following, you may be disqualified from receiving a bounty, or in some cases, disqualified from the entire program:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWithholding information about issues/drip-feeding issues.\u003c/li\u003e\n\u003cli\u003eAny physical attacks on Certinia property or personnel.\u003c/li\u003e\n\u003cli\u003ePerforming any form of attacks on Certinia employees or contractors.\u003c/li\u003e\n\u003cli\u003eSocial engineering attacks (e.g., phishing, smishing, vishing, etc.).\u003c/li\u003e\n\u003cli\u003eGenerating large amounts of noisy traffic such as heavy web fuzzing, scanners, spiders, scrapers, form spamming, etc.\u003c/li\u003e\n\u003cli\u003eIntentionally accessing, modifying or deleting sensitive information such as credentials.\u003c/li\u003e\n\u003cli\u003eAttempting to perform Denial of Service or brute-force attacks.\u003c/li\u003e\n\u003cli\u003eMake any configuration changes or execute state-changing commands on compromised servers (an echo is sufficient).\u003c/li\u003e\n\u003cli\u003ePivoting on issues to try to obtain access to additional internal resources. Having identified a way to obtain access to our internal infrastructure is normally sufficient. Feel free to ask us if you want to try to dig deeper and we may allow it.\u003c/li\u003e\n\u003cli\u003eCompromising internal Certinia accounts.\u003c/li\u003e\n\u003cli\u003eAttacks on any of our service providers or third-party integrations.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"e087fde8-2b46-4d6f-b337-de66a7f7ebd2","name":"In Scope Targets","targets":[{"id":"5c2570ef-fea5-4505-9f0b-cfc02f5e9229","uri":"https://financialforce.com","name":"*.financialforce.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"33514346-ecc0-457a-9275-fb54947adf3e","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"5c2570ef-fea5-4505-9f0b-cfc02f5e9229"},{"id":"487e9af0-2610-4813-a092-ea46f4cb6de1","name":"Wordpress","targetId":"5c2570ef-fea5-4505-9f0b-cfc02f5e9229"},{"id":"95db792c-091b-4c81-8d72-b09b1d065f09","name":"Cloud","targetId":"5c2570ef-fea5-4505-9f0b-cfc02f5e9229"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"5c2570ef-fea5-4505-9f0b-cfc02f5e9229"}],"recentChangeFlags":null},{"id":"6bcefe27-25e5-4f22-8614-ec6307687250","uri":"https://*.certinia.com","name":"*.certinia.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7f652eae-b553-4e1c-a2cc-9278b272c8f1","sortOrder":0},"sortOrder":0,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"6bcefe27-25e5-4f22-8614-ec6307687250"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"6bcefe27-25e5-4f22-8614-ec6307687250"},{"id":"487e9af0-2610-4813-a092-ea46f4cb6de1","name":"Wordpress","targetId":"6bcefe27-25e5-4f22-8614-ec6307687250"},{"id":"95db792c-091b-4c81-8d72-b09b1d065f09","name":"Cloud","targetId":"6bcefe27-25e5-4f22-8614-ec6307687250"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"6bcefe27-25e5-4f22-8614-ec6307687250"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"1551d143-940b-413d-b24b-b94e0e1b64f0","p1MaxCents":450000,"p1MinCents":300000,"p2MaxCents":200000,"p2MinCents":133700,"p3MaxCents":75000,"p3MinCents":50000,"p4MaxCents":35000,"p4MinCents":17500,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eAt Certinia we leverage AWS for our cloud infrastructure, Cloudflare for DNS, along with a good number of SaaS tools.\u003cbr\u003e\nFeel happy to report issues beyond what can be found under these domains (e.g., weaknesses based on OSINT) which may affect us. Essentially everything under the sun is in scope!\u003c/p\u003e\n\n\u003ch2\u003eNote on fuzzing and automated tools\u003c/h2\u003e\n\n\u003cp\u003eGenerating large volumes of traffic (more than 5 requests per second) with fuzzers, directory brute force tools, port/vulnerability scanners, etc. is forbidden. Please configure your tools to avoid exceeding these limits.\u003c/p\u003e","rewardRangeData":{"1":{"min":3000,"max":4500},"2":{"min":1337,"max":2000},"3":{"min":500,"max":750},"4":{"min":175,"max":350},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"dd9a90a5-11fe-4a79-af1d-94060d5c3c54","name":"Out of Scope","targets":[{"id":"35458b3d-a3c5-4dd7-8ef8-8bafb7aab9fd","uri":"","name":"gslink.financialforce.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f14785c4-5277-4824-84cf-83d5330da255","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eCVE-2021-26086 Limited Remote File Read/Include on Jira. We are aware of this issue and can confirm there is no security impact. The files exposed are all shipped with Jira out of the box. \u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"c6fa610f-d256-4794-abd2-3737a862c22d","code":"financialforce","state":"in_progress","endsAt":null,"bountyId":"aa9cbe50-b203-4d8e-bddc-b5ab144e91ef","startsAt":"2021-08-17T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/87cf/2179/789ee514/96318c0412eb5efd1b0174aec66a336b_Marquee_Monogram_Square_Black_Web__3_.png","logoBackgroundColor":"#000000","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2021-08-17T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/financialforce","changelogs":"/engagements/financialforce/changelog","submissions":null,"announcements":"/engagements/financialforce/announcements","hallOfFame":"/engagements/financialforce/hall_of_fames","crowdstream":"/engagements/financialforce/crowdstream"},"announcementsCount":5,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/financialforce/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=financialforce\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/financialforce/engagement_subscribers","engagementChangelogsUrl":"/engagements/financialforce/changelog","publishedAt":"2025-02-12T16:17:22.340Z","engagementChangelogUrl":"/engagements/financialforce/changelog/b69ed633-de6a-40f8-9636-86b963afa267","createUserFeedbacksUrl":"/engagements/financialforce/feedbacks","engagementCrowdstreamUrl":"/engagements/financialforce/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}