{"id":"04799316-ac45-47bf-b1e4-bb6641147f74","engagementId":"153f1599-5627-4f11-926c-50576b7a015e","data":{"brief":{"id":"6334b011-f515-4e07-9951-1615d9e65fb6","name":"IAG Transform Vulnerability Disclosure Engagement","tagline":"Airlines and Aviation","description":"\u003cp\u003eIAG Transform is the central transformation platform of International Airlines Group (IAG). We drive innovation, efficiency, and simplicity across finance, procurement, technology, and group-wide systems, enabling IAG to lead the future of aviation.\u003c/p\u003e\n\n\u003cp\u003eAt IAG Transform, we take security and privacy seriously.\u003cbr\u003e\nThis Vulnerability Disclosure Program (VDP) invites security researchers to report potential vulnerabilities in our systems safely, responsibly, and in coordination with us.\u003cbr\u003e\nWe aim to foster Good Faith Security Research and protect both researchers and our systems.\u003c/p\u003e\n\n\u003ch2\u003eRatings\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eIn cases where a finding is downgraded, we will provide the researcher with a comprehensive explanation detailing the reasoning behind the decision. Researchers will also be given the opportunity to appeal and present a case for reconsideration of the assigned priority.\u003c/p\u003e\n\n\u003ch2\u003eRules of Engagement\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eVulnerabilities must be submitted exclusively via the Bugcrowd platform and directed to our program. Submissions through other channels will not be accepted or acknowledged.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo not publicly disclose any details of a vulnerability, indicators of compromise, or sensitive information exposed by a vulnerability without explicit written authorisation from IAG Transform. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSubmissions must include detailed technical information with reproducible steps. Screenshots, proof-of-concept URLs, and clear descriptions are essential. Incomplete submissions may not be triaged.\u003cbr\u003e\nInclude the following HTTP header in any outgoing requests:\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eX-BugCrowd-traffic: \u0026lt;username\u0026gt;\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eUse your [username]@bugcrowdninja.com email alias when registering accounts.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eProvide your IP address in the bug report\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSubmit one vulnerability per submission, unless chaining is required to demonstrate impact.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIn the case of duplicate submissions, only the first valid submission will be accepted.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMultiple vulnerabilities stemming from a single root cause will be treated as one valid submission.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSocial engineering techniques (e.g. phishing, vishing, smishing) are strictly prohibited.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eResearchers must make a good faith effort to avoid privacy violations, data destruction, or service disruption. Only interact with accounts you own or have explicit permission to test.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eBy submitting a vulnerability, you agree to Bugcrowd’s Standard Disclosure Terms, Code of Conduct, Platform Behavior Standards and any additional terms outlined in this program.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo no harm: Do not exploit vulnerabilities beyond what is necessary to demonstrate their existence.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAvoid accessing IAG data in transit or at rest unless it is directly related to the vulnerability and necessary to prove its existence.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo not test or interact with accounts you do not own.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003ePhysical attacks on offices or data centers are strictly prohibited.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eData exfiltration is not permitted under any circumstances.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo not compromise the privacy, safety, intellectual property, or commercial interests of IAG personnel or third parties.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDenial of Service (DoS) testing is not allowed.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAvoid submitting a high volume of low-quality submissions.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you are ever unsure whether to proceed with testing, please contact our team via Bugcrowd for guidance.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eEligibility\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eYou must not be an employee, service provider, or contractor of IAG or its subsidiaries.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou must comply with any age, residency, or affiliation restrictions applicable in your jurisdiction\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRewards\u003c/h2\u003e\n\n\u003cp\u003eWe do not currently offer monetary or non-monetary rewards.\u003c/p\u003e","industryTagId":"2bf483dc-2f0b-4e2d-b7f0-568b8cc28809","targetsOverview":"\u003ch3\u003eOut of Scope\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003ePhysical systems (e.g., aircraft, offices)\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSocial engineering or phishing attempts\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eThird-party services not owned by IAG\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eNote\u003c/strong\u003e: IAG Transform utilizes several third-party providers and services, including some hosted on subdomains of \u003cstrong\u003eiaggbs.com\u003c/strong\u003e, \u003cstrong\u003eiairgroup.com\u003c/strong\u003e and \u003cstrong\u003eiag.ai\u003c/strong\u003e, which are considered out of scope for this program. As these systems are not owned by us, we cannot authorize security testing against them. We strongly encourage you to report any issues discovered within these services directly to the respective third-party. However, if you believe a vulnerability stems from IAG Transform’s misconfiguration or insecure implementation of a third-party service, we welcome your report and will investigate accordingly.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eIf you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to IAG Transform, you can report it to this engagement.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"f857200b-c672-46c7-9289-b96726c7bf51","name":"In scope","targets":[{"id":"ba4faa2c-50ec-4d39-ae33-a7d9cb6c5719","uri":"https://iaggbs.com/","name":"*.iaggbs.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"611d6bee-bfd1-4d34-8cb0-0fd46086b82a","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"ba4faa2c-50ec-4d39-ae33-a7d9cb6c5719"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ba4faa2c-50ec-4d39-ae33-a7d9cb6c5719"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"ba4faa2c-50ec-4d39-ae33-a7d9cb6c5719"}],"recentChangeFlags":null},{"id":"4a9059e5-661f-4a32-8e4e-e6b2383df8e3","uri":"https://iairgroup.com/","name":"*.iairgroup.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"64d75d9a-ff60-4796-a9ae-0f213c9b2fbe","sortOrder":1},"sortOrder":1,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"4a9059e5-661f-4a32-8e4e-e6b2383df8e3"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"4a9059e5-661f-4a32-8e4e-e6b2383df8e3"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"4a9059e5-661f-4a32-8e4e-e6b2383df8e3"}],"recentChangeFlags":null},{"id":"63e33345-d75d-4dd5-ba48-331dee440d43","uri":"https://iag.ai/","name":"*.iag.ai","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"780a35b5-64f2-433a-8240-b73d4e53bac1","sortOrder":2},"sortOrder":2,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"63e33345-d75d-4dd5-ba48-331dee440d43"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"63e33345-d75d-4dd5-ba48-331dee440d43"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"63e33345-d75d-4dd5-ba48-331dee440d43"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"63e33345-d75d-4dd5-ba48-331dee440d43"}],"recentChangeFlags":["entirely_new"]}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"153f1599-5627-4f11-926c-50576b7a015e","code":"iag-transform-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"0b88a7e0-7c26-4b45-9817-4a99aef56197","startsAt":"2025-08-19T06:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Transportation","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/8a91/f8af/81c88657/6cd8bbd701b263d2e6b6330da4481228_generated_image.png","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-08-19T06:00:00.033Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/iag-transform-vdp-pro","changelogs":"/engagements/iag-transform-vdp-pro/changelog","submissions":null,"announcements":"/engagements/iag-transform-vdp-pro/announcements","hallOfFame":"/engagements/iag-transform-vdp-pro/hall_of_fames","crowdstream":null},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/iag-transform-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":"updated","userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=iag-transform-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/iag-transform-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/iag-transform-vdp-pro/changelog","publishedAt":"2026-09-29T12:48:40.077Z","engagementChangelogUrl":"/engagements/iag-transform-vdp-pro/changelog/04799316-ac45-47bf-b1e4-bb6641147f74","createUserFeedbacksUrl":"/engagements/iag-transform-vdp-pro/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}