{"id":"546cdea2-812f-44b8-839d-db556e5cbb48","engagementId":"61580af6-041e-4adc-84bb-f0fa2de66da3","data":{"brief":{"id":"07782889-885d-4a5e-8ac7-6ffd80b84ce2","name":"Gartner Responsible Vulnerability Disclosure Program","tagline":"We deliver actionable, objective insight to executives and their teams. Our expert guidance and tools enable faster, smarter decisions and stronger performance on an organization’s mission-critical priorities. ","description":"\u003ch2\u003eOverview\u003c/h2\u003e\n\n\u003cp\u003eGartner is committed to maintaining the security of our systems and the information of our customers. We appreciate and encourage security researchers to alert us, and report potential vulnerabilities identified in any product, system or asset belonging to Gartner.\u003c/p\u003e\n\n\u003cp\u003eIf you believe you have identified a potential security vulnerability, please share it with us by following the submission guidelines below. \u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eThank you in advance for your submission!\u003c/strong\u003e We appreciate researchers assisting us in our security efforts.\u003c/p\u003e\n\n\u003ch2\u003eGartner Vulnerability Disclosure Program (VDP)\u003c/h2\u003e\n\n\u003cp\u003eWe accept vulnerability reports from independent security researchers, industry partners, vendors, customers and consultants. We recognize a security vulnerability as an unintended weakness or exposure that could be used to compromise the integrity, availability or confidentiality of our products and services. This vulnerability disclosure program (VDP) is offered to submit potential security findings.\u003c/p\u003e\n\n\u003cp\u003eBefore participating in our VDP, conducting any testing of Gartner-branded properties or submitting a report, you must first agree to abide by the terms and conditions found here. You further agree to abide by the \u003cstrong\u003e\u003ca href=\"https://www.gartner.com/en/about/policies/terms-of-use\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGartner Terms of Use\u003c/a\u003e\u003c/strong\u003e, and you agree to have your information processed in accordance with the \u003cstrong\u003e\u003ca href=\"https://www.gartner.com/en/about/policies/privacy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGartner Privacy Policy\u003c/a\u003e\u003c/strong\u003e. Failure to abide by the terms and conditions will result in your exclusion from consideration as a security researcher under our program.\u003c/p\u003e\n\n\u003ch2\u003eAuthorization\u003c/h2\u003e\n\n\u003cp\u003eIf you make a good-faith effort to comply with this policy during your security research, we will consider your research to be authorized, we will work with you to understand and resolve the issue quickly, and Gartner will not recommend or pursue legal action related to your research.\u003c/p\u003e\n\n\u003ch2\u003eOur commitment to researchers\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eTrust\u003c/strong\u003e. We maintain trust and confidentiality in our professional exchanges with security researchers.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eRespect\u003c/strong\u003e. We treat all researchers with respect and recognize your contribution to keeping our customers safe and secure.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eTransparency\u003c/strong\u003e. We will work with you to validate and remediate reported vulnerabilities in accordance with our commitment to security and privacy.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCommon good\u003c/strong\u003e. We investigate and remediate issues in a manner consistent with protecting the safety and security of those potentially affected by a reported vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eWhat we ask of researchers\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eTrust\u003c/strong\u003e. We request that you communicate about potential vulnerabilities in a responsible manner, providing sufficient time and information for our team to validate and address potential issues.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eRespect\u003c/strong\u003e. We request that researchers make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data during security testing.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCommon good\u003c/strong\u003e. We request that researchers act for the common good, protecting user privacy and security by refraining from publicly disclosing unverified vulnerabilities until our team has had time to validate and address reported issues. Public disclosure of the submission details of any identified or alleged vulnerability without express written consent from Gartner will deem the submission as noncompliant with this Vulnerability Disclosure Program.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003ch2\u003eScope\u003c/h2\u003e\n\n\u003cp\u003eThis policy applies to any digital assets owned, operated or maintained by Gartner, including public-facing websites.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":"\u003ch2\u003eIn addition\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou must not reside in a country currently on any sanction or embargoed country list where Gartner is established.\u003c/li\u003e\n\u003cli\u003eThe reported vulnerability must be original; the first person to submit a valid report shall be credited.\u003c/li\u003e\n\u003cli\u003eYou must not be the author of the vulnerable code.\u003c/li\u003e\n\u003cli\u003eYou must not attempt brute-force attacks, denial of service attacks, or user credential harvesting.\u003c/li\u003e\n\u003cli\u003eYou must not utilize social engineering of our employees and contractors to leverage exploitation of any kind.\u003c/li\u003e\n\u003cli\u003eIn the event of disclosure of personal data of another person, you are directed to cease the affecting activity, document steps to replicate, and submit the report as soon as possible.\u003c/li\u003e\n\u003cli\u003eIf you have discovered a vulnerability, do not disclose details of your findings publicly or to a third party.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eInformation you receive or collect about Gartner or its affiliates through the VDP, whether in oral, visual, written or electronic format, may be deemed proprietary and confidential (“Confidential Information”).\u003c/p\u003e\n\n\u003ch2\u003eVulnerability reporting\u003c/h2\u003e\n\n\u003cp\u003eGartner recommends that security researchers share the details of any suspected vulnerabilities across any asset owned, controlled or operated by Gartner \u003cem\u003e(or that would reasonably impact the security of Gartner and our users)\u003c/em\u003e using the web form below. The Gartner Application Security team will acknowledge receipt of each vulnerability report, conduct a thorough investigation and then take appropriate action for resolution.\u003c/p\u003e"},"scope":[{"id":"5c25ba13-59f9-4333-b871-3217e778860d","name":"top-level domains with wildcards","targets":[{"id":"df9fc246-bbe5-439d-82a7-7ed1eb2344e2","uri":"","name":"*.gartner.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"df12c8a2-18a0-4b89-a1ec-72c08904b58d","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"61580af6-041e-4adc-84bb-f0fa2de66da3","code":"gartner-disclosure","state":"in_progress","endsAt":null,"bountyId":"80990027-5104-4386-b9a4-95f8b6a7411f","startsAt":"2025-01-13T19:28:01Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/1074/2053/0917cb20/4a6f4eb56942c4765a0dd0429a2ce55d_gartner_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-01-13T19:28:01.511Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/gartner-disclosure","changelogs":"/engagements/gartner-disclosure/changelog","submissions":null,"announcements":"/engagements/gartner-disclosure/announcements","hallOfFame":"/engagements/gartner-disclosure/hall_of_fames","crowdstream":"/engagements/gartner-disclosure/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/gartner-disclosure/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=gartner-disclosure\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/gartner-disclosure/engagement_subscribers","engagementChangelogsUrl":"/engagements/gartner-disclosure/changelog","publishedAt":"2026-09-03T17:16:18.010Z","engagementChangelogUrl":"/engagements/gartner-disclosure/changelog/546cdea2-812f-44b8-839d-db556e5cbb48","createUserFeedbacksUrl":"/engagements/gartner-disclosure/feedbacks","engagementCrowdstreamUrl":"/engagements/gartner-disclosure/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}