{"id":"be93950f-8e03-4d64-9b15-a68c162de270","engagementId":"79ec4ca7-c672-4550-94e5-54f751d6927d","data":{"brief":{"id":"52843be9-6c9c-41b1-971f-b6db8d93aa77","name":"Inter-American Foundation - Vulnerability Disclosure Program","tagline":"Please submit your findings to our program ! ","description":"\u003cp\u003eThe Inter-American Foundation (IAF) is a U.S. government agency that invests in community-led development across Latin America and the Caribbean. The IAF engages local leaders, innovators, and entrepreneurs in underserved areas to create more prosperous, peaceful, and democratic communities.\u003c/p\u003e\n\n\u003cp\u003eThe IAF is committed to ensuring the security of the American public by protecting their information. The IAF’s Vulnerability Disclosure Policy (Policy) articulates the guidelines on acceptable vulnerability discovery activities and how to submit discovered vulnerabilities to the IAF.\u003c/p\u003e\n\n\u003cp\u003eThis Policy describes what systems and types of research are covered, how to report a vulnerability, and how long security researchers should wait before publicly disclosing vulnerabilities.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"2a38890b-c88e-4bc0-8db0-02059f3fafe6","targetsOverview":"\u003ch2\u003eAuthorization\u003c/h2\u003e\n\n\u003cp\u003eThe IAF does not authorize, permit, or otherwise allow (expressly or impliedly) any person, including any individual, group of individuals, consortium, partnership, or any other business or legal entity to engage in any security research or vulnerability disclosure activity that is inconsistent with this Policy or the law.  Engaging in any activities that are inconsistent with this policy or the law may be subject to criminal and/or civil liabilities.\u003c/p\u003e\n\n\u003cp\u003eIf a security researcher makes a good-faith effort to comply with this Policy, the IAF will consider your research to be authorized and will work with you to understand and resolve the issue quickly. The IAF will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party for activities that were conducted in accordance with this Policy, the IAF will make this authorization known.\u003c/p\u003e\n\n\u003cp\u003eInformation submitted under this Policy will be used only to mitigate or remediate vulnerabilities. If findings include newly discovered vulnerabilities that affect users of a particular product or service and not solely the Agency, the IAF may share the report with the Cybersecurity and Infrastructure Security Agency, where it will be handled under its coordinated vulnerability disclosure process. PII such as the security reporter’s name or contact information will not be shared without express permission.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eGuidelines\u003c/h2\u003e\n\n\u003cp\u003eUnder this Policy, “research” activities require security researchers to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCreate only two user accounts for testing. \u003c/li\u003e\n\u003cli\u003eStop testing, notify the Agency immediately, and not disclose the information to any other third party when there is confirmation that a vulnerability exists or when the security researcher encounters any sensitive data (including PII, financial information, or proprietary information or trade secrets of any party);\u003c/li\u003e\n\u003cli\u003eMake every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.\u003c/li\u003e\n\u003cli\u003eOnly use exploits to the extent necessary to confirm a vulnerability’s presence.\u003c/li\u003e\n\u003cli\u003eSecurity researchers must not use an exploit to compromise or exfiltrate data, establish persistent command line access, or use the exploit to pivot to other systems.\u003c/li\u003e\n\u003cli\u003eProvide the Agency a reasonable amount of time (90 calendar days) to resolve the issue before public disclosure;\u003c/li\u003e\n\u003cli\u003eNot submit a high volume of low-quality reports. A quality report should include the vulnerability type and description, a detailed description of the steps required to reproduce the vulnerability, the potential impact of exploitation, and technical information and related materials needed to reproduce the issue. OC scripts, screenshots, and screen captures are encouraged. Exploitable code should be properly labeled and protected.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eScope\u003c/h2\u003e\n\n\u003cp\u003eAny service not expressly listed above, such as any connected services, are excluded from scope and are not authorized for testing. Additionally, vulnerabilities found in systems from our vendors fall outside of this policy’s scope and should be reported directly to the vendor according to their disclosure policy (if any). If you aren’t sure whether a system is in scope or not, contact us at \u003ca href=\"mailto:support@bugcrowd.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esupport@bugcrowd.com\u003c/a\u003e before starting your research  (or at the security contact for the system’s domain name listed in the .gov WHOIS).\u003c/p\u003e\n\n\u003cp\u003eThough we develop and maintain other internet-accessible systems or services, we ask that active research and testing only be conducted on the systems and services covered by the scope of this document. If there is a particular system not in scope that you think merits testing, please contact us to discuss it first. We will increase the scope of this policy over time.\u003c/p\u003e\n\n\u003ch2\u003eTest methods\u003c/h2\u003e\n\n\u003cp\u003eThe following test methods are not authorized:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNetwork denial of service (DoS or DDoS) tests or other tests that impair access to or damage a system or data.\u003c/li\u003e\n\u003cli\u003ePhysical testing (e.g. office access, open doors, tailgating), social engineering (e.g. phishing, vishing), or any other non-technical vulnerability testing.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eWhat you can expect from us\u003c/h2\u003e\n\n\u003cp\u003eWhen you choose to share your contact information with us, we commit to coordinating with you as openly and as quickly as possible.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eFor reports submitted in compliance with this Policy, the Agency will acknowledge receipt within 5 business days.\u003c/li\u003e\n\u003cli\u003eThe Agency will attempt to timely validate and triage submissions, implement corrective actions if appropriate, and inform security researchers of the disposition of reported vulnerabilities following internal VDP Standard Operating Procedures (SOP).\u003c/li\u003e\n\u003cli\u003eThe IAF will report on the reported vulnerability and disclose, if possible, the steps being taken during the remediation process, including issues or challenges that may delay resolution.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via \u003ca href=\"mailto:support@bugcrowd.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esupport@bugcrowd.com\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"9012ca94-d6d9-426f-9b58-db400393fc50","name":"In Scope ","targets":[{"id":"7ea3f4c7-69dc-4d8d-a902-a0abc7fa18a5","uri":"","name":"*iaf.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"142c8757-bfb6-4fa3-9f4f-9557c49a0ccb","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"79ec4ca7-c672-4550-94e5-54f751d6927d","code":"iaf-vdp","state":"in_progress","endsAt":null,"bountyId":"80c7e8fd-4db2-4a82-aaef-aea582119519","startsAt":"2023-01-10T12:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Government","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/fb66/f11a/3c76d522/5ed6bffb8f5bacc1b8c13824c01c03c6_1623851136544.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2023-01-10T12:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/iaf-vdp","changelogs":"/engagements/iaf-vdp/changelog","submissions":null,"announcements":"/engagements/iaf-vdp/announcements","hallOfFame":"/engagements/iaf-vdp/hall_of_fames","crowdstream":"/engagements/iaf-vdp/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/iaf-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=iaf-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/iaf-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/iaf-vdp/changelog","publishedAt":"2022-12-13T23:54:37.280Z","engagementChangelogUrl":"/engagements/iaf-vdp/changelog/be93950f-8e03-4d64-9b15-a68c162de270","createUserFeedbacksUrl":"/engagements/iaf-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/iaf-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}