{"id":"b781e690-8e42-445a-ba6f-afc5496f65de","engagementId":"09509827-c8cd-4870-9794-6e541bb2bd3d","data":{"brief":{"id":"2e29565a-5523-4bad-8da8-3b36dd107e6b","name":"Glean Technologies Public Engagement","tagline":"Glean is an AI-powered work assistant - across all your company's data.","description":"\u003ch2\u003eGlean Responsible Vulnerability Disclosure\u003c/h2\u003e\n\n\u003cp\u003eGlean is an enterprise search and work assistant designed to streamline the process of finding necessary information across various workplace tools such as chat, email, document repositories, bug tracking tools, customer support systems, and internal wikis. It aims to address the challenge of fragmented workplace information, making it easier for teams to accomplish their goals by providing exactly the information needed at the right time. Glean operates by searching all of your apps across your entire company, understanding context, language, behavior, and relationships to find personalized answers to your questions. \u003c/p\u003e\n\n\u003cp\u003eAt Glean we take security very seriously and recognise the value external security researchers bring to the overall security of Glean’s solution. If you believe that you have found a security vulnerability on Glean’s in-scope sites/domains/paths, we encourage you to let us know straight away. We will investigate all legitimate reports and do our best to quickly fix the problem.\u003c/p\u003e\n\n\u003cp\u003eBefore reporting, please review this page including the process and exceptions sections.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, an explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Glean Technologies not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Glean Technologies, you can report it to this program. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eThis bounty is part of the Atlassian Marketplace Bounty Program\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003eScope\u003c/h2\u003e\n\n\u003cp\u003eThe current scope for security researchers include Glean’s search and assistant. The assistant can be accessed through Glean search.\u003c/p\u003e\n\n\u003ch3\u003eIn-scope entry points:\u003c/h3\u003e\n\n\u003cp\u003eFrontend portal: https://app.glean.com/login?qe=https://bug-bounty-be.glean.com\u0026amp;skip_to_sso=1 \u003cbr\u003e\nBackend endpoint: bug-bounty-be.glean.com\u003c/p\u003e\n\n\u003ch3\u003eIn-scope paths:\u003c/h3\u003e\n\n\u003cp\u003eGlean dashboard search\u003cbr\u003e\nEverything in the tabs: Directory, Knowledge, Chat\u003c/p\u003e\n\n\u003cp\u003eNew features: HTML Artifacts, Code Writer, File upload, Code interpreter, External Links in Glean Chat.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eHTML Artifacts:\u003c/strong\u003e\u003cbr\u003e\nHTML Artifacts is a Glean Canvas feature that allows AI-generated HTML/CSS/JavaScript code to be executed in a sandboxed environment directly within the Canvas interface. Users can ask the LLM to create interactive visualizations, infographics, diagrams (Mermaid charts), and apps, the generated code renders in a sandboxed iframe.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eExample trigger:\u003c/em\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNavigate to Glean Chat\u003c/li\u003e\n\u003cli\u003eAsk the assistant to create an HTML artifact, e.g.:\n\n\u003cul\u003e\n\u003cli\u003e\"Create an interactive pie chart showing product adoption breakdown\"\u003c/li\u003e\n\u003cli\u003e\"Show me a Mermaid diagram of our authentication flow in HTML canvas\"\u003c/li\u003e\n\u003cli\u003e\"Build an interactive calculator\"\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eThe LLM generates HTML code that executes in a sandboxed preview\u003c/li\u003e\n\u003cli\u003eUsers can interact with the rendered content and use actions like \"Download as SVG\"\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eCode Writer action:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eCode Writer is an AI‑powered code action in Assistant and Glean Agents that helps debug, edit code, address comments and open draft PRs end‑to‑end with enterprise‑grade security and admin controls, no local setup required. Unlike solutions like Cursor Background tasks, Code Writer runs securely within a customer's dedicated VPC, giving them complete control over data residency and network access.\u003cbr\u003e\nIt’s ideal for small/medium features, refactors, tests, and docs, addressing comments work, and can be activated from Assistant, Agents, or Slack.\u003cbr\u003e\nOutcome: Ship small, low‑risk changes faster with fewer handoffs and less context switching.\u003c/p\u003e\n\n\u003cp\u003eExample trigger: “Update markdown https://github.com/gleanbugbounty/mcp-server-bugbounty/blob/main/CONTRIBUTING.md by replacing every occurence of mise with foo. Create a PR.”\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eFile Upload:\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThe file upload feature in Glean Chat allows users to upload various types of files directly from their local computer and query their content in real-time. Here are the key capabilities of the file upload feature:\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eSupported File Formats:\u003c/em\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDocument Files: pdf, doc, docx, pages\u003c/li\u003e\n\u003cli\u003eSpreadsheet Files: xls, xlsx, numbers\u003c/li\u003e\n\u003cli\u003ePresentation Files: ppt, pptx, key\u003c/li\u003e\n\u003cli\u003eText Files: csv, json, xml, txt\u003c/li\u003e\n\u003cli\u003eWeb Files: html, css\u003c/li\u003e\n\u003cli\u003eCode Files: java, py, js, ts, cpp, c, ipynb, sql, sh, go, yaml, log\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eKey Features:\u003c/em\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eFile Upload: Users can upload multiple files (up to 5 files, each with a maximum size of 10 MB) directly from their local computer.\u003c/li\u003e\n\u003cli\u003eReal-Time Querying: Users can query the text content of the uploaded files immediately after upload.\u003c/li\u003e\n\u003cli\u003eDocument Metadata: The chat UI displays document metadata, such as title and file type.\u003c/li\u003e\n\u003cli\u003eFile Deletion: Users can delete uploaded files before submitting their first query. Once a query is submitted, the files cannot be deleted directly from the chat session but will be removed when the chat session history is deleted.\u003c/li\u003e\n\u003cli\u003eSecurity: Files are parsed and scanned for malware before being stored within the cloud project. Any files with detected malware will have an error for upload.\u003c/li\u003e\n\u003cli\u003ePrivacy: Files uploaded will only be accessible to the user who uploaded them.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThe content of all files uploaded is retained for 24 hours.\u003cbr\u003e\nFile metadata is retained for 30 days after a chat session is started and then deleted.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eExample usage:\u003c/em\u003e\u003c/strong\u003e Upload a pdf and ask Glean to summarise its content.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eCode Interpreter:\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThe code interpreter in Glean Chat is designed to execute code in a secure, controlled environment, primarily for analyzing structured text files like spreadsheets and CSVs. Here are the key capabilities and features of the code interpreter:\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eSupported File Types:\u003c/em\u003e\u003cbr\u003e\nThe code interpreter is primarily used for .xls, .xlsx, and .csv files.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKey Features:\u003c/em\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eQuery Context: The code interpreter is triggered based on the context of the query and the file type. It is used for tasks such as summarization, filtering, calculation, or analysis of the spreadsheet.\u003c/li\u003e\n\u003cli\u003eText Explanation: After each step of the code interpreter analysis, a text explanation is provided.\u003c/li\u003e\n\u003cli\u003eIntermediate Spreadsheets: Users can view a preview of the spreadsheet and download the generated CSV files.\u003c/li\u003e\n\u003cli\u003eSandbox Environment: The code interpreter runs in a sandbox environment to ensure security and isolation. Each chat session with a code interpreter invocation is assigned a unique sandbox instance.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eExample usage:\u003c/em\u003e\u003c/strong\u003e Upload a .csv file containing a series of numbers and ask Glean to perform an arithmetic operation on them.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eExternal Links\u003c/strong\u003e\nExternal links feature allows users to submit external URLs as part of a chat message. Glean Chat will be able to fetch the contents of external web links present in the user messages and use them to answer user queries.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThis feature currently works only in the \u003cstrong\u003ePublic Knowledge\u003c/strong\u003e app within Glean chat and covers unauthenticated sites with static content (e.g., HTML, PDF, DOCX, PPTX). \u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003e\u003cstrong\u003eExample usage:\u003c/strong\u003e\u003c/em\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSummarizing news articles\u003c/li\u003e\n\u003cli\u003eAccessing public disclosures, including research and financial disclosures\u003c/li\u003e\n\u003cli\u003eParsing public APIs and developer documentation\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003eNew features from 2025-10-31:\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eCode Writer action:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eCode Writer is an AI‑powered code action in Assistant and Glean Agents that helps debug, edit code, address comments and open draft PRs end‑to‑end with enterprise‑grade security and admin controls, no local setup required. Unlike solutions like Cursor Background tasks, Code Writer runs securely within a customer's dedicated VPC, giving them complete control over data residency and network access.\u003cbr\u003e\nIt’s ideal for small/medium features, refactors, tests, and docs, addressing comments work, and can be activated from Assistant, Agents, or Slack.\u003cbr\u003e\nOutcome: Ship small, low‑risk changes faster with fewer handoffs and less context switching.\u003c/p\u003e\n\n\u003cp\u003eExample trigger: “Update markdown https://github.com/gleanbugbounty/mcp-server-bugbounty/blob/main/CONTRIBUTING.md by replacing every occurence of mise with foo. Create a PR.”\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eChat Sharing V2\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eChat Sharing V2 lets you share a reliable, permission-aware snapshot of a Glean Chat conversation via a link—so others see the same content you saw, without needing to regenerate the chat. It’s designed to be comprehensive, consistent, convenient, and compartmentalized.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eWhat it is\u003c/em\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eFrozen, view‑only snapshot of a chat session that preserves the exact messages at the time of sharing, so recipients see the same content as the sharer.\u003c/li\u003e\n\u003cli\u003ePermission-aware redaction: any cited documents/agents the viewer cannot access are redacted or substituted, protecting sensitive information while preserving context.\u003c/li\u003e\n\u003cli\u003eSimple share link flow modeled on familiar assistants; the link is easy to copy and share with teammates.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eHow to use (end users)\u003c/em\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOpen the chat you want to share.\u003c/li\u003e\n\u003cli\u003eClick Share (top-right). The link is generated and easy to copy; a modal lets you adjust who can view.\u003c/li\u003e\n\u003cli\u003eSet permissions to specific people, groups, or organization scope as allowed by admin policy. Viewers get a read‑only snapshot; they cannot edit the original chat.\u003c/li\u003e\n\u003cli\u003eSend the link to recipients. If they lack access to cited sources, those items appear redacted; the answer text remains visible for review.\nTip: Use chat sharing when you need colleagues to quickly consume findings, follow the exact steps you used, or review the conversation for decision‑making—without re‑running the session.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eKnown vulnerabilities\u003c/em\u003e\u003cbr\u003e\nThe following vulnerabilities are not already known and not rewardable(will be considered P5):\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIDOR in chat sharing to specific people, groups or organization scope. \u003c/li\u003e\n\u003cli\u003eIDOR in snapshot edit by chat recipients.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCredentials:\u003c/h2\u003e\n\n\u003ch3\u003eHow to access and authenticate:\u003c/h3\u003e\n\n\u003cp\u003eFill the form \u003ca href=\"https://forms.gle/magxnfQTJHWpuNGU9\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAccess to Glean bug bounty\u003c/a\u003e by logging into your google account (gmail) and submit. If you need access to an additional email id, submit the form again from a different google account. You will receive a confirmation email from Google Groups within 24 hours. Check the spam folder if you don't find an email from Google Groups in your inbox.\u003cbr\u003e\nReach out to security@glean.com if you have any questions.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eEligible Vulnerability Categories\u003c/h3\u003e\n\n\u003cp\u003eWe encourage a coordinated disclosure of the following eligible web application vulnerabilities:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCross-site scripting (XSS)\u003c/li\u003e\n\u003cli\u003eCross-site request forgery in a privileged context (CSRF)\u003c/li\u003e\n\u003cli\u003eServer-side code execution (RCE)\u003c/li\u003e\n\u003cli\u003eServer-side request forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eXML External Entity Attacks (XXE)\u003c/li\u003e\n\u003cli\u003eSQL Injection (SQLi)\u003c/li\u003e\n\u003cli\u003eAuthentication or Authorization flaws including Access Control Vulnerabilities(Insecure Direct Object References issues, etc)\u003c/li\u003e\n\u003cli\u003eStored Injection Vulnerabilities on client and server side\u003c/li\u003e\n\u003cli\u003eDirectory/Path Traversal\u003c/li\u003e\n\u003cli\u003eInformation Disclosure\u003c/li\u003e\n\u003cli\u003eSignificant Security Misconfiguration\u003c/li\u003e\n\u003cli\u003eLLM related attacks\n\n\u003cul\u003e\n\u003cli\u003eData exfiltration \u003c/li\u003e\n\u003cli\u003eInsecure output handling with a possible exploitation. Avoid duplicate reports if this is achieved through XSS.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eNote that third-party applications or websites not owned or controlled by Glean are not within the scope of the program.\u003c/p\u003e\n\n\u003cp\u003eTo receive credit, you must be the first reporter of a vulnerability. When submitting a vulnerability, please provide concise steps to reproduce that are easily understood.\u003c/p\u003e\n\n\u003ch3\u003eAcceptable Criteria for P1 and P2 submissions\u003c/h3\u003e\n\n\u003cp\u003eShould have a valid and reproducible exploit leading to significant loss of business critical data. The final severity will be determined by Glean based on the ease of exploitation and impact.\u003c/p\u003e\n\n\u003cp\u003eNote: All IDORs in user generated content (Collections, Prompts, Answers, GoLinks, Announcements etc) will be categorised as P4/P5.\u003c/p\u003e\n\n\u003ch3\u003eRules, Exclusions, and Scopes\u003c/h3\u003e\n\n\u003cp\u003eAny domain/property of Glean Technologies  not listed in the targets section is strictly out of scope (for more information please see the out of scope and exclusions sections below). \u003c/p\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cp\u003eAnything not declared as a target or in scope above should be considered out of scope for the purposes of this bug bounty. While we encourage any submission affecting the security of a Glean web property, unless evidence is provided demonstrating exploitability, the following finding types are excluded from this program:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eBlind XSS must not return any user data that you do not have access to (e.g. Screen shots, cookies that aren't owned by you, etc); when testing for blind XSS, please use the least invasive test possible (e.g. calling 1x1 image or nonexistent page on your webserver, etc).\u003c/li\u003e\n\u003cli\u003eSelf-XSS [to be valid, cross-site scripting issues must be exploitable via reflected, stored or DOM-based attacks]\u003c/li\u003e\n\u003cli\u003eSimilarly, any XSS where local access is required (i.e. User-Agent Header injection) will not be accepted. The only exception will be if you can show a working off-path MiTM attack that will allow for the XSS to trigger.\u003c/li\u003e\n\u003cli\u003eWhen testing, please exercise caution if injecting on any form that may be publicly visible - such as forums, etc. Before injection, please make sure your payload can be removed from the site. If it cannot be easily removed, please check with security@glean.com before performing the testing.\u003c/li\u003e\n\u003cli\u003eNo pivoting or post exploitation attacks (i.e. using a vulnerability to find another vulnerability) are allowed on this program. DO NOT under any circumstance leverage a finding to identify further issues.\u003c/li\u003e\n\u003cli\u003eAny Glean Technologies  website (e.g. https://www.glean.com/ ), or any customer domains (e.g. https://customer.glean.com) is out of scope for this bounty unless explicitly included in the scope.\u003c/li\u003e\n\u003cli\u003eCustomer cloud instances and data are explicitly out of scope.\u003c/li\u003e\n\u003cli\u003eAny repository that you are not an owner of - do not impact Glean Technologies , or Atlassian customers in any way.\u003c/li\u003e\n\u003cli\u003eOnly the latest version of our products are eligible for a reward.\u003c/li\u003e\n\u003cli\u003eAny internal or development services\u003c/li\u003e\n\u003cli\u003eThe use of Automated scanners is strictly prohibited (we have these tools too - don't even think about using them)\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g. Stack Traces, application or server errors).\u003c/li\u003e\n\u003cli\u003eHTTP 404 codes/pages or other HTTP non-200 codes/pages.\u003c/li\u003e\n\u003cli\u003eFingerprinting / banner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eSoftware version disclosure.\u003c/li\u003e\n\u003cli\u003eDisclosure of known public files or directories, (e.g. robots.txt).\u003c/li\u003e\n\u003cli\u003eClickjacking/UI redressing with no practical security impact.\u003c/li\u003e\n\u003cli\u003eCSRF on forms that are available to anonymous users (e.g. the contact form).\u003c/li\u003e\n\u003cli\u003eCSRF attacks that require knowledge of the CSRF token (e.g. attacks involving a local machine).\u003c/li\u003e\n\u003cli\u003eOpen redirects with low security impact (exceptions are those cases where the impact is higher such as stealing OAuth tokens)\u003c/li\u003e\n\u003cli\u003eLogout and other instances of low-severity Cross-Site Request Forgery (logout CSRF)\u003c/li\u003e\n\u003cli\u003eContent spoofing / text injection\u003c/li\u003e\n\u003cli\u003eCross-site tracing (XST)\u003c/li\u003e\n\u003cli\u003ePresence of application or web browser ‘autocomplete’ or ‘save password’ functionality.\u003c/li\u003e\n\u003cli\u003eLack of Secure/HTTPOnly flags on non-sensitive Cookies.\u003c/li\u003e\n\u003cli\u003eLack of Security Speedbump when leaving the site.\u003c/li\u003e\n\u003cli\u003eWeak Captcha / Captcha Bypass.\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force and account lockout not enforced.\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration via Login Page or Forgot Password Page error messages\u003c/li\u003e\n\u003cli\u003ePassword and account recovery policies, such as reset link expiration or password complexity\u003c/li\u003e\n\u003cli\u003eOPTIONS HTTP method enabled.\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration.\u003c/li\u003e\n\u003cli\u003eMissing cookie flags on non-sensitive cookies.\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers e.g.\n\n\u003cul\u003e\n\u003cli\u003eStrict-Transport-Security.\u003c/li\u003e\n\u003cli\u003eX-Frame-Options.\u003c/li\u003e\n\u003cli\u003eX-XSS-Protection.\u003c/li\u003e\n\u003cli\u003eX-Content-Type-Options.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy, X-Content-Security-Policy, X-WebKit-CSP.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy-Report-Only.\u003c/li\u003e\n\u003cli\u003eCache-Control and Pragma\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eHTTP/DNS cache poisoning.\u003c/li\u003e\n\u003cli\u003eSSL/TLS Issues, e.g.\u003c/li\u003e\n\u003cli\u003eSSL Attacks such as BEAST, BREACH, Renegotiation attack.\u003c/li\u003e\n\u003cli\u003eSSL Forward secrecy not enabled.\u003c/li\u003e\n\u003cli\u003eSSL weak/insecure cipher suites.\u003c/li\u003e\n\u003cli\u003eNo Load testing (DoS/DDoS etc) is allowed on the instance.\u003c/li\u003e\n\u003cli\u003eThis includes application DoS as well as network DoS.\u003c/li\u003e\n\u003cli\u003eVulnerabilities that are limited to unsupported browsers will not be accepted (i.e. \"this exploit only works in IE6/IE7\").\u003c/li\u003e\n\u003cli\u003eKnown vulnerabilities in used libraries, or the reports that a Glean product uses an outdated third party library unless you can prove exploitability.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect SPF records of any kind.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect DMARC records of any kind.\u003c/li\u003e\n\u003cli\u003eSource code disclosure vulnerabilities.\u003c/li\u003e\n\u003cli\u003eInformation disclosure of non-confidential information (e. g. issue id, project id, commit hashes).\u003c/li\u003e\n\u003cli\u003eMethods to extend product trial periods\u003c/li\u003e\n\u003cli\u003eThe ability to upload/download viruses or malicious files to the platform.\u003c/li\u003e\n\u003cli\u003eEmail bombing/Flooding/rate limiting\u003c/li\u003e\n\u003cli\u003eEXIF Geolocation Data\u003c/li\u003e\n\u003cli\u003eSubdomain takeovers (these are considered P5 at this time)\u003c/li\u003e\n\u003cli\u003eLLM related attacks\n\n\u003cul\u003e\n\u003cli\u003ePrompt injection\u003c/li\u003e\n\u003cli\u003eJailbreaking\u003c/li\u003e\n\u003cli\u003eModel DoS\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eHow to Submit a vulnerability\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eRead these guidelines, ensuring that you follow the process and your vulnerability is in scope.\u003c/li\u003e\n\u003cli\u003eUse the Bugcrowd report a bug process to report vulnerabilities.\u003c/li\u003e\n\u003cli\u003eEvery vulnerability report should be unique for a vulnerability.\u003c/li\u003e\n\u003cli\u003eIt is mandatory to evaluate the Confidentiality, Availability and Integrity metrics and provide a CVSS v3+ score while submitting a vulnerability report.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eResponsible Disclosure reporting instructions\u003c/h3\u003e\n\n\u003cp\u003eYour report must include the following information:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eContact email address\u003c/li\u003e\n\u003cli\u003eVulnerability description\u003c/li\u003e\n\u003cli\u003eVulnerability locations\u003c/li\u003e\n\u003cli\u003eSteps to reproduce and Validation steps\u003c/li\u003e\n\u003cli\u003eRecommended fix\u003c/li\u003e\n\u003cli\u003eAssumed impact\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eTerms \u0026amp; Conditions\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou give us reasonable time to investigate and mitigate an issue that you report before making any information about the report public or sharing such information with others.\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou must ensure that customer data is not affected in any way as a result of your testing. Please ensure you're being non-destructive whilst testing and are only testing on instances that you own.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIn addition to above, customer instances are not to be accessed in any way (i.e. no customer data is accessed, customer credentials are not to be used or \"verified\")\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you believe you have found sensitive customer data (e.g., login credentials, API keys etc) or a way to access customer data (i.e. through a vulnerability) report it, but do not attempt to successfully validate if/that it works.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cem\u003eUse of any automated tools/scanners is strictly prohibited\u003c/em\u003e and will lead to you being removed from the program (trust us, we have those tools too).\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eReports need to be submitted in plain text (associated pictures/videos are fine as long as they're in standard formats). Non-plain text reports (e.g. PDF, DOCX) will be asked to be resubmitted in plain text.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eGrants/awards are at the discretion of Glean Technologies  and we withhold the right to grant, modify or deny grants. But we'll be fair about it.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eTax implications of any payouts are the sole responsibility of the reporter.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo NOT conduct non-technical attacks such as social engineering, phishing or unauthorized access to infrastructure.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo NOT test the physical security of Glean Technologies  offices, employees, equipment, etc.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eThis bounty follows Bugcrowd’s standard disclosure terms.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou do not exploit a security issue that you discover for any reason.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou do not violate any other applicable laws or regulations.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou do not interact with an individual account (which includes modifying or accessing data from the account) without the account owner's explicit consent in writing, which you must produce upon request.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou make a good faith effort to avoid privacy violations and disruptions to others, including (but not limited to) unauthorized access to or destruction of data, and interruption or degradation of our services. You must not intentionally violate any applicable laws or regulations, including (but not limited to) laws and regulations prohibiting the unauthorized access to data.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you inadvertently access another person's data or Glean company data without authorisation while investigating an issue, you must promptly cease any activity that might result in further access of user or Glean company data and notify Glean what information was accessed (including a full description of the contents of the information) and then immediately delete the information from your system. Continuing to access another person's data or company data may demonstrate a lack of good faith and disqualify you from any benefit of the Safe Harbour Provisions described below. You must also acknowledge the inadvertent access in any related bug bounty report that you may subsequently submit. You may not share the inadvertently accessed information with anyone else.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eNot be employed by or a contractor/vendor of Glean or its subsidiaries or affiliates, or be an immediate family member of a person employed by Glean or its subsidiaries or affiliates (defined for these purposes as including spouse, domestic partner, parent, legal guardian, legal ward, child, and sibling, and each of their respective spouses, and individuals living in the same household as such individuals).\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003ePlease send all reports via report a bug in Bugcrowd. Please note we may only reply to the first reporter of a significant issue. Any reward payments will be made through BugCrowd with no exceptions or alternatives provided. \u003c/p\u003e\n\n\u003ch3\u003eBug Bounty Process\u003c/h3\u003e\n\n\u003cp\u003eYour submission will be reviewed and validated by Glean’s internal Security Team.\u003c/p\u003e\n\n\u003cp\u003eDepending upon the severity of your issue, it may take us time to respond to you, please do not contact our staff directly but use the above email contact method instead.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen submitting a vulnerability, please provide concise steps to reproduce that are easily understood.\u003c/li\u003e\n\u003cli\u003eIf the same vulnerability is found on multiple hosts associated with the same asset/domain, please include all vulnerable hosts in a single report.\u003c/li\u003e\n\u003cli\u003eWhen duplicates occur, we consider the first report that was received to be treated as unique, and all subsequent reports will be marked as duplicates. (Glean determines duplicates in its sole discretion and is not obligated to share details on prior similar reports.)\u003c/li\u003e\n\u003cli\u003eReport a security bug: identify a vulnerability in our services or infrastructure which creates a security or privacy risk. (Note that Glean ultimately determines the risk of an issue, and that many software bugs are not security issues.) Report the vulnerability upon discovery or as soon as is feasible.\u003c/li\u003e\n\u003cli\u003eReport a security bug involving one of the products or services that are within the scope of the programme; we specifically exclude certain types of potential security issues, listed under “Ineligible Vulnerabilities” below. \u003c/li\u003e\n\u003cli\u003eWe may retain any communications about security issues that you report for as long as we deem necessary for programme purposes, and we may cancel or modify this programme at any time.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003ePublic Disclosure\u003c/h3\u003e\n\n\u003cp\u003eBefore disclosing an issue publicly we require that you first request permission from us. Glean Technologies  will process requests for public disclosure on a per report basis. Requests to publicly disclose an issue that has not yet been fixed for customers will be rejected. Any researcher found publicly disclosing reported vulnerabilities without Glean Technologies’s written consent will have any allocated bounty withdrawn and disqualified from the program.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ecreate a ticket with Bugcrowd Support\u003c/a\u003e for clarification before proceeding.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"a8b753f1-81a4-4b78-83e2-90a7ec00a201","name":"In Scope Targets","targets":[{"id":"1b56dbf4-5521-4c61-b3d4-6091926dc3d5","uri":"https://app.glean.com/login?qe=https://bug-bounty-be.glean.com\u0026skip_to_sso=1","name":"Frontend portal: https://app.glean.com/login?qe=https://bug-bounty-be.glean.com\u0026skip_to_sso=1","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ef80a0ae-23fd-457b-a4c7-a3815998f619","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"1b56dbf4-5521-4c61-b3d4-6091926dc3d5"},{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"1b56dbf4-5521-4c61-b3d4-6091926dc3d5"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"1b56dbf4-5521-4c61-b3d4-6091926dc3d5"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"1b56dbf4-5521-4c61-b3d4-6091926dc3d5"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"1b56dbf4-5521-4c61-b3d4-6091926dc3d5"}],"recentChangeFlags":null},{"id":"929db997-6c52-4784-8ce5-1e5fe9d92a4f","uri":"","name":"Backend endpoint: bug-bounty-be.glean.com","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e1ded570-b987-405a-b3cd-1c76efc1f956","sortOrder":1},"sortOrder":1,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"929db997-6c52-4784-8ce5-1e5fe9d92a4f"},{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"929db997-6c52-4784-8ce5-1e5fe9d92a4f"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"929db997-6c52-4784-8ce5-1e5fe9d92a4f"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"929db997-6c52-4784-8ce5-1e5fe9d92a4f"}],"recentChangeFlags":null},{"id":"cf9c2448-a447-4631-971a-a83f6f09d52e","uri":"https://marketplace.atlassian.com/apps/1222714/scio-search-crawler-for-confluence?hosting=cloud\u0026tab=overview","name":"Scio Search Crawler for Confluence- https://marketplace.atlassian.com/apps/1222714/scio-search-crawler-for-confluence?hosting=cloud\u0026tab=overview","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9768f76b-449b-4523-bce4-9e0861155184","sortOrder":2},"sortOrder":2,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"cf9c2448-a447-4631-971a-a83f6f09d52e"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"cf9c2448-a447-4631-971a-a83f6f09d52e"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"cf9c2448-a447-4631-971a-a83f6f09d52e"}],"recentChangeFlags":null},{"id":"2fb945bb-31b0-4069-8f8e-da84baa777ae","uri":"https://marketplace.atlassian.com/apps/1222715/scio-search-crawler-for-jira?hosting=cloud\u0026tab=overview","name":"Scio Search Crawler for Jira- https://marketplace.atlassian.com/apps/1222715/scio-search-crawler-for-jira?hosting=cloud\u0026tab=overview","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9b8a399e-0e57-4f84-a8f7-13216a4772e7","sortOrder":3},"sortOrder":3,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"2fb945bb-31b0-4069-8f8e-da84baa777ae"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2fb945bb-31b0-4069-8f8e-da84baa777ae"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"2fb945bb-31b0-4069-8f8e-da84baa777ae"}],"recentChangeFlags":null},{"id":"f56c979b-8b34-4c61-b0fe-7037245061e5","uri":"https://marketplace.atlassian.com/apps/1229003/glean-activity-plugin-for-jira-cloud?hosting=cloud\u0026tab=overview","name":"Glean Activity Plugin for Jira Cloud- https://marketplace.atlassian.com/apps/1229003/glean-activity-plugin-for-jira-cloud?hosting=cloud\u0026tab=overview","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"cd74c342-0c25-47ef-81e6-1c6febcd3aa4","sortOrder":4},"sortOrder":4,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"f56c979b-8b34-4c61-b0fe-7037245061e5"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f56c979b-8b34-4c61-b0fe-7037245061e5"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"f56c979b-8b34-4c61-b0fe-7037245061e5"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"22bf3b5e-8764-4b37-999a-210018f05e97","p1MaxCents":500000,"p1MinCents":500000,"p2MaxCents":250000,"p2MinCents":250000,"p3MaxCents":60000,"p3MinCents":60000,"p4MaxCents":20000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003e\u003cstrong\u003eNote\u003c/strong\u003e: Glean (scio) apps in Atlassian marketplace are used internally by Glean to connect with Atlassian data source. The Atlassian marketplace in itself is not in scope of this program. Any submission which is not related to Glean is explicitly out of scope.\u003c/p\u003e","rewardRangeData":{"1":{"min":5000,"max":5000},"2":{"min":2500,"max":2500},"3":{"min":600,"max":600},"4":{"min":200,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"09509827-c8cd-4870-9794-6e541bb2bd3d","code":"glean-technologies-public","state":"in_progress","endsAt":null,"bountyId":"5e9e8a28-1b71-42c0-8175-f3d1e794364d","startsAt":"2024-10-09T13:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/407f/875f/ea521c46/eb77553c0170a95019adf8462f45652a_gleanwork_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-10-09T13:00:00.463Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/glean-technologies-public","changelogs":"/engagements/glean-technologies-public/changelog","submissions":null,"announcements":"/engagements/glean-technologies-public/announcements","hallOfFame":"/engagements/glean-technologies-public/hall_of_fames","crowdstream":"/engagements/glean-technologies-public/crowdstream"},"announcementsCount":7,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/glean-technologies-public/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=glean-technologies-public\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/glean-technologies-public/engagement_subscribers","engagementChangelogsUrl":"/engagements/glean-technologies-public/changelog","publishedAt":"2026-02-05T15:30:17.011Z","engagementChangelogUrl":"/engagements/glean-technologies-public/changelog/b781e690-8e42-445a-ba6f-afc5496f65de","createUserFeedbacksUrl":"/engagements/glean-technologies-public/feedbacks","engagementCrowdstreamUrl":"/engagements/glean-technologies-public/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}