{"id":"c2b5060d-5f00-4a6d-9af7-77c90fc6fe07","engagementId":"6097b046-77b7-4cd6-a18d-83a34e5153fb","data":{"brief":{"id":"a0d6a5d1-f7e7-4b80-86eb-65ce84e38853","name":"Fivetran","tagline":"Fivetran automates data movement from disparate sources into your destination.","description":"\u003cp\u003eFivetran, the global leader in data movement, helps customers use their data to power everything from AI applications and ML models, to predictive analytics and operational workloads. The Fivetran platform reliably and securely centralizes data from hundreds of SaaS applications and databases into any cloud destination — whether deployed on-premises, in the cloud or in a hybrid environment. Thousands of global brands, including Autodesk, Condé Nast, JetBlue and Morgan Stanley, trust Fivetran to move their most valuable data assets to fuel analytics, drive operational efficiencies and power innovation.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect and Fivetran believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings and rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eOnly Critical (P1), Severe (P2), and Moderate (P3) submissions will be rewarded\u003c/strong\u003e. P4 findings will be marked as Not Applicable.\u003c/p\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eA Bugcrowd account is required. Please sign up for a Fivetran account using your @bugcrowdninja.com email address only. Do not use personal email addresses. \u003c/p\u003e\n\n\u003cp\u003eIf your testing requires two separate Fivetran accounts, please add \"+1\" to your email address for the secondary account. Using your @bugcrowdninja.com address helps us identify you.\u003c/p\u003e\n\n\u003cp\u003eFor more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eRules of Engagement\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eIf you are able to access or modify personal data of Fivetran customers or other sensitive data, immediately contact Fivetran - do not attempt to conduct post-exploitation work.\u003c/li\u003e\n\u003cli\u003eDo not use, share, publish, or disclose information obtained in the course of identifying issues. After submitting you must delete, purge, and/or destroy all copies of information or digital samples.\u003c/li\u003e\n\u003cli\u003eDo not attempt a denial-of-service attack.\u003c/li\u003e\n\u003cli\u003eDo not use ChatGPT, DeepSeek, Google Gemini or any AI tools during your research. You may not disclose any information within these platforms.\u003c/li\u003e\n\u003cli\u003ePlease contact support@bugcrowd.com for any escalations. Do not contact Fivetran or Fivetran aliases to follow up on submissions. Doing so can result in point reduction or program expulsion.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eParticipation Criteria\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eBy participating, you represent that you (i) are at least 18 years old, (ii) are not located in, organized under the laws of, or ordinarily resident in a jurisdiction subject to comprehensive U.S. sanctions, (iii) are not identified on the U.S. Treasury Department’s Specially Designated Nationals and Blocked Persons List (“SDN List”) or any other U.S. restricted-party list, and (iv) are not, and are not owned or controlled (\u0026gt;50 %), by any person or entity designated on the U.S. Department of Commerce Entity List, Unverified List, or Military End-User List, or otherwise subject to U.S. export-control restrictions.\u003c/li\u003e\n\u003cli\u003eYou may not submit vulnerability reports while physically present in any jurisdiction subject to comprehensive U.S. sanctions.\u003c/li\u003e\n\u003cli\u003eYou must not be a current employee or immediate family member of Fivetran or any third party managing Fivetran’s digital assets or infrastructure.\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eAs of Sept 25th, 2026, effective immediately, we are pausing testing on our Capture the Flag target until further notice.\u003c/p\u003e\n\n\u003cp\u003eWe apologize for the inconvenience and will let you know as soon as we have more information as to when the program will re-open.\u003c/p\u003e\n\n\u003cp\u003eIn the interim, Bugcrowd and Fivetran Inc. will be working together to continue triaging and validating all submissions that have come in to-date.\u003c/p\u003e\n\n\u003cp\u003eWe appreciate your patience. If you have any questions, please create a ticket with Bugcrowd Support (https://bugcrowd-support.freshdesk.com/support/tickets/new) to get them answered.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eAs of July 8, 2025 we have removed Census from our bounty program. Please stop any further testing on this site.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Fivetran not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Fivetran, you can report it to this engagement. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eTarget Information\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eFivetran platform documentation is available at: \u003ca href=\"https://fivetran.com/docs/getting-started\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://fivetran.com/docs/getting-started\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAccess to pipeline data \u003c/li\u003e\n\u003cli\u003eAccount authentication \u003c/li\u003e\n\u003cli\u003e\n\u003ca href=\"https://fivetran.com/docs/connector-sdk#connectorsdk\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eFivetran Connector SDK\u003c/a\u003e \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eCredentials\u003c/h3\u003e\n\n\u003cp\u003eTo gain access to the applications, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou may register for Fivetran accounts here: https://fivetran.com/signup\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eAccess/Traffic Identification\u003c/h3\u003e\n\n\u003cp\u003ePlease add the following header to your HTTP traffic to prevent interruptions and verify non-malicious behavior:\u003cbr\u003e\n\u003ccode\u003eX-Bug-Bounty:\u0026lt;bugcrowdusername\u0026gt;\u003c/code\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP4 \u0026amp; P5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\n\n\u003cul\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting\u003c/li\u003e\n\u003cli\u003eEmail bombing/flooding\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSocial Engineering\n\n\u003cul\u003e\n\u003cli\u003eFor example, attempts to steal cookies, fake login pages to collect credentials.\u003c/li\u003e\n\u003cli\u003ePhishing.\u003c/li\u003e\n\u003cli\u003ePhysical attacks against Facilities / Property.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerabilities resulting from compatibility with external services.\n\n\u003cul\u003e\n\u003cli\u003eFor example, when sources provide weak/vulnerable auth methods that Fivetran must use to provide a connector.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eCredential Stuffing / Password Spraying.\u003c/li\u003e\n\u003cli\u003eAny type of brute force attacks.\u003c/li\u003e\n\u003cli\u003eClickjacking\u003c/li\u003e\n\u003cli\u003eSubmissions related to past or present data dumps or leaked credentials.\u003c/li\u003e\n\u003cli\u003eEngaging in the trade of stolen/breached user credentials or use leaked credentials dumps in the testing.\u003c/li\u003e\n\u003cli\u003eModifying data residing in an account that does not belong to you.\u003c/li\u003e\n\u003cli\u003eAccessing or downloading data beyond the minimum required to demonstrate a vulnerability.\u003c/li\u003e\n\u003cli\u003eMaking any changes to the system configurations, files, or data.\u003c/li\u003e\n\u003cli\u003eIntroducing a backdoor in any system.\u003c/li\u003e\n\u003cli\u003eAttacking/interacting with our end users in any way.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 30 days has gone by\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2025, we would consider it in-scope on 01/31/2025\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eNever attempt non-technical attacks such as social engineering, phishing, or physical attacks against our employees, users, or infrastructure.\u003c/li\u003e\n\u003cli\u003eDo not attempt to gain access to another user’s account or data other than the target account. \u003c/li\u003e\n\u003cli\u003eDo not attempt denial of service attacks\u003c/li\u003e\n\u003cli\u003eDo not perform any attack that could harm the reliability/integrity of our services or data.\u003c/li\u003e\n\u003cli\u003eDo not publicly disclose a bug before it has been fixed.\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo not impact other users with your testing, this includes testing for vulnerabilities in portals you do not own.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eInteracting or manipulate other stakeholders and their associated accounts including:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSocial engineering attacks\u003c/li\u003e\n\u003cli\u003ePhishing attacks\u003c/li\u003e\n\u003cli\u003ePhysical attacks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eThird party providers and services\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eAll HVR products are excluded from this reward.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003eLeaked Credentials\u003c/h2\u003e\n\n\u003cp\u003eIf you happen to identify vulnerabilities involving data that has been exposed or leaked such as dark web forums or leaked credential sites. You can report it to this engagement. However, be aware that it is only eligible for points-based compensation. This policy helps maintain the highest standard of operational confidentiality, integrity, and compliance.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"82879ee6-70df-452b-a312-a2b03078cd0d","name":"In Scope Targets","targets":[{"id":"4e40f27a-44c7-4379-9008-9fa62a7a4530","uri":"https://fivetran.com/login","name":"*.fivetran.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2e4ceb0e-959b-4e40-b895-13f8879d9540","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"4e40f27a-44c7-4379-9008-9fa62a7a4530"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"4e40f27a-44c7-4379-9008-9fa62a7a4530"},{"id":"e82bba17-848b-4f2b-a2a5-58d2a83530d4","name":"Kubernetes","targetId":"4e40f27a-44c7-4379-9008-9fa62a7a4530"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"f4c4a82c-dee3-41d5-b611-6918d3953b79","p1MaxCents":750000,"p1MinCents":250000,"p2MaxCents":250000,"p2MinCents":100000,"p3MaxCents":100000,"p3MinCents":50000,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eFivetran products, excluding Out of Scope assets.\u003c/p\u003e\n\n\u003cp\u003eAny finding or (sub)subdomain that is not listed in scope but is confirmed owned by Fivetran may be accepted upon review.\u003c/p\u003e","rewardRangeData":{"1":{"min":2500,"max":7500},"2":{"min":1000,"max":2500},"3":{"min":500,"max":1000},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"8eea122f-fde6-4914-bf15-e6ce64f77285","name":"Out of Scope","targets":[{"id":"f4902db4-af0d-4671-8b16-da27366616cb","uri":"","name":"Any internal, staging, or development services.","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"60a46b92-1e54-4774-8b96-595790ad50fa","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"d6929c4f-500e-407d-a4cf-e09880f762f7","uri":"","name":"Social engineering against Fivetran Support or Fivetran Employees","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2f408dd5-6ad9-4262-bcfc-37842f4a3684","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"35b34588-5605-443f-b8df-884ecd46ddde","uri":"","name":"*.db.fivetran.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2eba084d-bb84-4764-bdda-36848a710eb9","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"722a00af-50ef-425b-9ece-36e4681b8916","uri":"","name":"testing-datalake.fivetran.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e469582e-62fa-4d50-981c-b054a15df898","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"7d5c4ddc-2117-4a34-9f4f-33bb17e30715","uri":"https://shop.fivetran.com","name":"shop.fivetran.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"fb0dc88f-25e7-48ce-bf47-e164d81b1dd1","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null},{"id":"3cae2653-d9c3-4638-a44a-df6c329bc180","uri":"https://status.fivetran.com/","name":"status.fivetran.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e856fc4e-d356-4342-af4e-7f62084b4a7d","sortOrder":5},"sortOrder":5,"tags":null,"recentChangeFlags":null},{"id":"6e9539ab-2388-4172-9ea8-249ffe35c558","uri":"https://support.fivetran.com","name":"support.fivetran.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"05109579-dad8-4bc0-ade8-814de6a2cbcb","sortOrder":6},"sortOrder":6,"tags":null,"recentChangeFlags":null},{"id":"31426a1b-1959-4cce-821e-f4083ce085a8","uri":"https://community-stage.fivetran.com","name":"community-stage.fivetran.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5c6f2585-db09-4bd0-894f-b358738d599d","sortOrder":7},"sortOrder":7,"tags":null,"recentChangeFlags":null},{"id":"d6ea4960-1daa-424a-b055-125e5ec934cc","uri":"https://trust.fivetran.com","name":"trust.fivetran.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6bd3e856-4462-41fb-b90e-8d5a65c59fac","sortOrder":8},"sortOrder":8,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":2,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"6097b046-77b7-4cd6-a18d-83a34e5153fb","code":"fivetran-mbb-og","state":"in_progress","endsAt":null,"bountyId":"c6f10fbf-8b74-4fc9-a932-5a1ee5e3ffef","startsAt":"2025-03-18T19:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/46cf/b3c2/3104783e/c9b59fd127212baca5448f2779a7b8ad_fivetran_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-03-18T19:00:02.193Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/fivetran-mbb-og","changelogs":"/engagements/fivetran-mbb-og/changelog","submissions":null,"announcements":"/engagements/fivetran-mbb-og/announcements","hallOfFame":"/engagements/fivetran-mbb-og/hall_of_fames","crowdstream":null},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/fivetran-mbb-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=fivetran-mbb-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/fivetran-mbb-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/fivetran-mbb-og/changelog","publishedAt":"2026-09-25T14:00:44.206Z","engagementChangelogUrl":"/engagements/fivetran-mbb-og/changelog/c2b5060d-5f00-4a6d-9af7-77c90fc6fe07","createUserFeedbacksUrl":"/engagements/fivetran-mbb-og/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}