{"id":"c404df2a-d924-4789-99c8-3db04a5f4d86","engagementId":"75eb3f17-0489-4318-bf6f-cf0437307147","data":{"brief":{"id":"40125a3c-26b4-40b1-aedf-931276cf606d","name":"Just Eat Takeaway.com","tagline":"Lead, Deliver, Care - Justeattakeaway.com","description":"\u003cp\u003eJust Eat Takeaway.com values the security of its customers, partners and employees. We invite security researchers to test our public-facing defenses, helping us strengthen our platform.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings and rewards:\u003c/h2\u003e\n\n\u003cp\u003eWe follow the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e for the initial classification of reported issues. This means certain vulnerability types have a capped to maximum level of severity. We may adjust prioritization based on real-world likelihood and business impact to JustEatTakeaway.com ’s platform. Submissions based purely on automated scanning output are generally not accepted unless they uncover a clearly significant issue. If a submission is reprioritized or downgraded, we will provide a detailed explanation and invite the researcher to appeal with further evidence or reasoning.\u003c/p\u003e\n\n\u003ch2\u003eFocus areas:\u003c/h2\u003e\n\n\u003cp\u003eWe prioritize actionable vulnerabilities with direct business or operational impact: account takeovers, payment bypasses, customer data disclosure, authentication bypasses, and impactful business logic flaws. Reports must demonstrate clear exploitability, and findings without proper impact explanation may be considered bugs rather than security issues.\u003c/p\u003e","industryTagId":"c85cd17d-3c78-44ca-a00b-40aff928e114","targetsOverview":"\u003chr\u003e\n\n\u003ch1\u003eGeneral Guidance\u003c/h1\u003e\n\n\u003cp\u003eWe align with the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e, which defines the maximum severity for each vulnerability type. This means that certain findings, such as \u003cstrong\u003eReflected XSS\u003c/strong\u003e, are capped at a maximum of \u003cstrong\u003eP3\u003c/strong\u003e, regardless of impact or context. Severity assessments are bound by the vulnerability category and do not escalate beyond the capped level defined in the taxonomy.\u003c/p\u003e\n\n\u003cp\u003eSome resources, URLs, and applications share the same codebase. As a result, identical vulnerabilities across different domains, URLs, or subdomains will be treated as duplicates. However, some functionalities may differ, meaning certain features could exist on one domain but not on another. This applies to “staging”, “dev” and other environments. If you find the same vulnerability on multiple instances, such as the same URL affecting different API endpoints or domains, please report them in a single ticket to be considered for additional recognition rewards. \u003cstrong\u003eOtherwise, they will be treated as duplicates.\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eTesting is only authorized on the targets listed as In-Scope. Any domain/property of JustEatTakeaway not listed in the targets section is out of scope. This includes any/all subdomains not listed above.  If you believe you've identified a vulnerability on a system outside the scope, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before submitting.\u003c/p\u003e\n\n\u003cp\u003eBehavior that compromises the stability and integrity of the site is \u003cstrong\u003eout of scope\u003c/strong\u003e (specifically the production environment). For example, do not target other user's data (use one of your other sets of credentials), delete/remove/edit parts of the site, engage any sort of DoS attack, and/or compromise any target's ability to function for other users.\u003c/p\u003e\n\n\u003cp\u003eFor all other sites in this scope, purchasing of goods on the platform will be at your \u003cstrong\u003eown risk \u0026amp; cost\u003c/strong\u003e, we hope to provide additional test credentials, payments \u0026amp; restaurants in the future.\u003c/p\u003e\n\n\u003ch3\u003eUser Agent Requirement\u003c/h3\u003e\n\n\u003cp\u003ePlease add the following header to your HTTP traffic to prevent interruptions and verify non-malicious behavior. This will help the Just Eat team identify that activity is coming from a researcher on the program and ensure that your testing is not blocked or interrupted.\u003cbr\u003e\n\u003ccode\u003eX-Bug-Bounty:\u0026lt;bugcrowdusername\u0026gt;\u003c/code\u003e\u003c/p\u003e\n\n\u003ch3\u003eCredentials\u003c/h3\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities or reports lacking a working Proof of Concept (PoC), require significant user action (e.g., disabling browser security settings) or are tied to outdated or unsupported devices/software.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eVulnerabilities dependent on random customer IDs (basketID, orderID, sessionID etc.), f.e. get/update basket content by knowing it's ID, are considered to \u003cstrong\u003ebe not eligible\u003c/strong\u003e and be marked as Out of Scope. We are interested only in methods that allows to disclose such ID's in a mass and without interaction.\u003c/li\u003e\n\u003cli\u003eSupply chain attacks without proof of JET infrastructure callback (IP/hostname).\u003c/li\u003e\n\u003cli\u003eAI generated reports without proper research, validation, or containing hallucinations will be rejected and marked as Non-applicable. Similarly, automated tool results without manual verification and working PoC are not eligible.\u003c/li\u003e\n\u003cli\u003ePublic buckets with static content, source maps, or generic info disclosure (versions, tech stack, errors).\u003c/li\u003e\n\u003cli\u003eMissing server-side checks without privilege escalation (low-to-high privilege). Admin-to-admin or high-to-high privilege issues are considered as low priority bug.\u003c/li\u003e\n\u003cli\u003eSubdomain takeovers without proof of successful exploitation, dangling CNAMEs are not eligible.\u003c/li\u003e\n\u003cli\u003eDev and staging environments operate with demo data, so debug functionality available in these environments is not eligible unless paired with critical findings affecting production.\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\n\n\u003cul\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting bypass attempts\u003c/li\u003e\n\u003cli\u003eEmail bombing flooding\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSession persistence concerns (e.g., valid session remaining post-logout).\u003c/li\u003e\n\u003cli\u003eVulnerabilities that are \u003cem\u003ebest practices\u003c/em\u003e or \u003cem\u003erecommendations\u003c/em\u003e, including:\n\n\u003cul\u003e\n\u003cli\u003eSSL/TLS configurations\u003c/li\u003e\n\u003cli\u003eDNS settings (e.g., SPF, DMARC)\u003c/li\u003e\n\u003cli\u003eCookie configurations (e.g., flags, expiration policies)\u003c/li\u003e\n\u003cli\u003eMobile security mechanisms (e.g., pinning, protection measures)\u003c/li\u003e\n\u003cli\u003eAbsence of standard security headers (e.g., HSTS, CSP)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eOpen redirects are marked as informative and closed\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 30 days has gone by\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2025, we would consider it in-scope on 31/01/2025\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eInteracting or manipulate other stakeholders and their associated accounts including:\n\n\u003cul\u003e\n\u003cli\u003eSocial engineering attacks\u003c/li\u003e\n\u003cli\u003ePhishing attacks\u003c/li\u003e\n\u003cli\u003ePhysical attacks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eThird party providers and services\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePotential post-exploitation scenarios\u003c/strong\u003e: If you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity.\u003c/li\u003e\n\u003cli\u003eGenerally every subdomain pointing to *.leadfamly.com or *.playable.com.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eStolen/Breached Credentials\u003c/h2\u003e\n\n\u003cp\u003eIf you happen to identify vulnerabilities involving data that has been exposed or leaked such as dark web forums or leaked credential sites. You can report it to this engagement. However, be aware that it is only eligible for points-based compensation. This policy helps maintain the highest standard of operational confidentiality, integrity, and compliance.\u003c/p\u003e\n\n\u003ch2\u003eStatement of non-eligibility\u003c/h2\u003e\n\n\u003cp\u003eEmployees of JustEatTakeaway.com  and all its subsidiaries (including former employees that separated from Takeaway.com within the prior 12 months), contingent workers, contractors and their personnel, and consultants, as well as their immediate family members and persons living in the same household are not eligible to receive bounties or rewards of any kind under this program.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eSafe Harbor:\u003c/h1\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003cli\u003eWe’re committed to supporting good-faith research and collaboration. If you’re unsure whether an action is permitted, please refer bugcrowd and rules before attempting\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"8f359a6b-c8a5-48a4-9990-5bbda195197a","name":"Business assets","targets":[{"id":"3b3a1940-add1-4f7a-821a-2f3ee0934e10","uri":"https://www.thuisbezorgd.nl/","name":"*.thuisbezorgd.nl","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"340ff615-2d1a-4abb-9d7d-59abcab0d29b","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"3b3a1940-add1-4f7a-821a-2f3ee0934e10"}],"recentChangeFlags":null},{"id":"7f7a2529-7f2e-45b0-8167-1847deae017b","uri":"https://takeaway.com","name":"*.takeaway.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"8b807c1f-2a12-476a-abee-a6c07884ffa6","sortOrder":2},"sortOrder":2,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7f7a2529-7f2e-45b0-8167-1847deae017b"}],"recentChangeFlags":null},{"id":"ec65f9a2-2113-4082-984a-b3e84ae9dcff","uri":"https://skipthedishes.com","name":"*.skipthedishes.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"77b305b4-a72e-423b-beaa-890ce1173429","sortOrder":3},"sortOrder":3,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ec65f9a2-2113-4082-984a-b3e84ae9dcff"}],"recentChangeFlags":null},{"id":"415cad15-2191-45a6-bb7a-47cb37ec5855","uri":"https://lieferando.de","name":"*.lieferando.de","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"23b75100-03c8-4667-9aa2-199aa3b8542a","sortOrder":5},"sortOrder":5,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"415cad15-2191-45a6-bb7a-47cb37ec5855"}],"recentChangeFlags":null},{"id":"e7ff33b7-16f8-4cbc-a347-4f3d0a0bfb3d","uri":"https://pyszne.pl","name":"*.pyszne.pl","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ef721380-e0a3-4865-9680-9a0751a0976a","sortOrder":6},"sortOrder":6,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e7ff33b7-16f8-4cbc-a347-4f3d0a0bfb3d"}],"recentChangeFlags":null},{"id":"ab562971-d4f8-4424-ac91-0cee11f05583","uri":"https://bistro.sk","name":"*.bistro.sk","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c2999c74-ab82-44c9-b892-b69e5663cefc","sortOrder":7},"sortOrder":7,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ab562971-d4f8-4424-ac91-0cee11f05583"}],"recentChangeFlags":null},{"id":"cf3b2d15-07fc-4d4b-8876-26230aceb1ce","uri":"https://just-eat.es","name":"*.just-eat.es","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7428cd8c-8f8b-4b26-93c8-b0177f32e5a8","sortOrder":8},"sortOrder":8,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"cf3b2d15-07fc-4d4b-8876-26230aceb1ce"}],"recentChangeFlags":null},{"id":"31d88bb5-dcfa-45f3-842e-b2bed1abb4b3","uri":"https://www.just-eat.co.uk","name":"*.just-eat.co.uk","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"da19eba8-5917-4083-9a82-1e459d880edc","sortOrder":9},"sortOrder":9,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"31d88bb5-dcfa-45f3-842e-b2bed1abb4b3"}],"recentChangeFlags":null},{"id":"38fe0ef1-fcba-4827-a36e-6637bf392e93","uri":"https://just-eat.ch","name":"*.just-eat.ch","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"13ae841b-a487-450a-9d88-98109d9c5dba","sortOrder":10},"sortOrder":10,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"38fe0ef1-fcba-4827-a36e-6637bf392e93"}],"recentChangeFlags":null},{"id":"65d789a9-5a7d-41cb-99aa-45390c8006ab","uri":"https://10bis.co.il","name":"*.10bis.co.il","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d92851a3-d78f-4012-91ac-7874f1a18ceb","sortOrder":11},"sortOrder":11,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"65d789a9-5a7d-41cb-99aa-45390c8006ab"}],"recentChangeFlags":null},{"id":"863525bf-4508-45fb-965f-09d7e39d7953","uri":"https://scoober.com","name":"*.scoober.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b6ebf80b-b34f-40f1-a915-56ff70e23cdb","sortOrder":12},"sortOrder":12,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"863525bf-4508-45fb-965f-09d7e39d7953"}],"recentChangeFlags":null},{"id":"f5abdf96-1e89-4f01-ab8a-7ac75bb94ff8","uri":"https://jet-external.com","name":"*.jet-external.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"63e2202a-66e7-4a50-9249-71fd57ad14bf","sortOrder":13},"sortOrder":13,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f5abdf96-1e89-4f01-ab8a-7ac75bb94ff8"}],"recentChangeFlags":null},{"id":"676e57b4-cac2-4c67-9aae-fba5cc44d4f2","uri":"https://just-eat.com","name":"*.just-eat.com ","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6101c8af-8e98-46cd-891c-bc29fc9862cc","sortOrder":13},"sortOrder":13,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"676e57b4-cac2-4c67-9aae-fba5cc44d4f2"}],"recentChangeFlags":null},{"id":"349afd1b-9463-453b-bdc8-5f31ecae349f","uri":"https://skippayments.com","name":"*.skippayments.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"036df27f-13ad-43e7-8d06-2979f1ec596d","sortOrder":14},"sortOrder":14,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"349afd1b-9463-453b-bdc8-5f31ecae349f"}],"recentChangeFlags":null},{"id":"18d77fca-35c0-418d-a76a-9e135130c845","uri":"https://just-eat.io/","name":"*.just-eat.io","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"0e8192f8-0e2a-4b6f-b7b4-e64fe5dc97ac","sortOrder":14},"sortOrder":14,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"18d77fca-35c0-418d-a76a-9e135130c845"}],"recentChangeFlags":null},{"id":"f416c1b2-395a-4421-9502-a599babacb5a","uri":"https://just-eat.co.il","name":"*.just-eat.co.il","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"51acebbb-87bc-43a0-a730-04443ec0ce9e","sortOrder":15},"sortOrder":15,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f416c1b2-395a-4421-9502-a599babacb5a"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":{"id":"53e5038a-0fd4-46d5-af64-d8693eac3bcb","p1MaxCents":450000,"p1MinCents":350000,"p2MaxCents":250000,"p2MinCents":150000,"p3MaxCents":50000,"p3MinCents":30000,"p4MaxCents":10000,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":500000},"descriptionHtml":"\u003cp\u003eSame vulnerabilities found across applications, domains, subdomains, or environments (e.g., staging, dev) - may share the same codebase and will be treated as duplicates unless clear functional differences exist; related findings should be submitted in a single report for potential recognition, otherwise they may not be eligible for separate rewards.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFocus areas\u003c/strong\u003e - Authentication and authorization issues, business logic abuse\u003c/p\u003e","rewardRangeData":{"1":{"min":3500,"max":4500},"2":{"min":1500,"max":2500},"3":{"min":300,"max":500},"4":{"min":0,"max":100},"5":{"min":null,"max":null},"programMax":5000},"recentChangeFlags":null},{"id":"96de5d1d-3c81-43ac-8e7a-cd3db8d87807","name":"Mobile applications","targets":[{"id":"0d1c4387-058d-4159-ad3f-34c48ff976e6","uri":"https://play.google.com/store/apps/developer?id=Takeaway.com","name":"Takeaway.com","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"dc651d6e-9743-46ea-98a4-7715f0c7ebed","sortOrder":0},"sortOrder":0,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"0d1c4387-058d-4159-ad3f-34c48ff976e6"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"0d1c4387-058d-4159-ad3f-34c48ff976e6"}],"recentChangeFlags":null},{"id":"f985607a-0bd3-4056-b533-09fc323fbf51","uri":"https://play.google.com/store/apps/developer?id=Just-Eat+Holding+Limited","name":"Just-Eat Holding Limited","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"893d0835-70f4-481b-92a0-f4d72ced4d12","sortOrder":1},"sortOrder":1,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"f985607a-0bd3-4056-b533-09fc323fbf51"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"f985607a-0bd3-4056-b533-09fc323fbf51"}],"recentChangeFlags":null},{"id":"11ccc395-10e8-483a-b157-4ff013dc8e81","uri":"https://play.google.com/store/apps/developer?id=10bis.co.il+ltd.","name":"10bis.co.il ltd.","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e9b5d31c-3ae7-459e-832e-e4cd500a941d","sortOrder":2},"sortOrder":2,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"11ccc395-10e8-483a-b157-4ff013dc8e81"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"11ccc395-10e8-483a-b157-4ff013dc8e81"}],"recentChangeFlags":null},{"id":"ff677ebc-ed4e-461a-b843-5dcfbd22154b","uri":"https://play.google.com/store/apps/developer?id=Skip+Canada","name":"Skip Canada","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c3b78cdb-fd00-4fad-9c2b-f56d4b9882bf","sortOrder":3},"sortOrder":3,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"ff677ebc-ed4e-461a-b843-5dcfbd22154b"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"ff677ebc-ed4e-461a-b843-5dcfbd22154b"}],"recentChangeFlags":null},{"id":"441cf183-a9a6-497d-b03c-6bd1f293cc83","uri":"https://apps.apple.com/nz/developer/just-eat-com/id383091095","name":"Just-Eat.com","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a9a8f37f-f3d7-4dd9-80bd-2d892502a419","sortOrder":4},"sortOrder":4,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"441cf183-a9a6-497d-b03c-6bd1f293cc83"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"441cf183-a9a6-497d-b03c-6bd1f293cc83"}],"recentChangeFlags":null},{"id":"5ca6c41a-497a-4fcf-9d40-9918d5d6c751","uri":"https://apps.apple.com/it/developer/takeaway-com-central-core-b-v/id329472762","name":"Takeaway.com Central Core B.V.","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5828c766-878e-48c4-9799-dbd84f1413e5","sortOrder":5},"sortOrder":5,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"5ca6c41a-497a-4fcf-9d40-9918d5d6c751"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"5ca6c41a-497a-4fcf-9d40-9918d5d6c751"}],"recentChangeFlags":null},{"id":"61b458cd-164c-47d3-baf0-9be9956a8090","uri":"https://apps.apple.com/us/developer/skipthedishes/id969229980","name":"SkipTheDishes","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c0c409ad-6772-4124-9221-8b151adea936","sortOrder":6},"sortOrder":6,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"61b458cd-164c-47d3-baf0-9be9956a8090"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"61b458cd-164c-47d3-baf0-9be9956a8090"}],"recentChangeFlags":null},{"id":"91d417d1-6fcb-48c3-b0aa-46073fb0c241","uri":"https://apps.apple.com/us/developer/10bis-co-il-ltd/id434368194","name":"10bis.co.il, Ltd","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e6d01d6b-9be9-4c7d-9e9e-6811b8915a93","sortOrder":7},"sortOrder":7,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"91d417d1-6fcb-48c3-b0aa-46073fb0c241"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"91d417d1-6fcb-48c3-b0aa-46073fb0c241"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":3,"description":null,"rewardRange":{"id":"4b169d8a-5e1e-4563-91ab-4c0f4b981933","p1MaxCents":450000,"p1MinCents":350000,"p2MaxCents":250000,"p2MinCents":150000,"p3MaxCents":50000,"p3MinCents":30000,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eServer-side vulnerabilities discovered through mobile applications fall under \u0026quot;Business Platforms and APIs\u0026quot; scope. Vulnerabilities requiring rooted/jailbroken devices are out-of-scope. Vulnerabilities requiring ADB access, physical device access, install of the malware app or WebView exploitation are also out-of-scope. We are looking for 0-click or 1-click vulnerabilities.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFocus areas:\u003c/strong\u003e Secrets leakage, mobile misconfigurations \u003c/p\u003e","rewardRangeData":{"1":{"min":3500,"max":4500},"2":{"min":1500,"max":2500},"3":{"min":300,"max":500},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"a0c7c39e-89b7-45f0-ac52-87ead6554e6f","name":"Other assets","targets":[{"id":"fecffb0d-ce76-493e-bb93-9a9fa49fb971","uri":"https://www.justeattakeaway.com","name":"*.justeattakeaway.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"1c1f7e90-6e2a-43d4-ae85-847af462ce5b","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"fecffb0d-ce76-493e-bb93-9a9fa49fb971"}],"recentChangeFlags":null},{"id":"551f9b99-62b2-48f6-84cc-a6f7531aa445","uri":"https://api.justeat-int.com","name":"*.justeat-int.com","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f73f5e31-c3f4-4eb4-b032-ae076c883e44","sortOrder":2},"sortOrder":2,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"551f9b99-62b2-48f6-84cc-a6f7531aa445"}],"recentChangeFlags":null},{"id":"da39b577-20f2-4594-9a40-8511c64f21a0","uri":"https://yourdelivery.de","name":"*.yourdelivery.de","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"25c5393a-8437-4a47-b6ae-db42eb5d87c6","sortOrder":3},"sortOrder":3,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"da39b577-20f2-4594-9a40-8511c64f21a0"}],"recentChangeFlags":null},{"id":"64fd49a3-223b-460b-b312-d28d60a4e4af","uri":"https://just-data.io","name":"*.just-data.io","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"69a87b07-9cd3-4623-8d97-2123a2d108f2","sortOrder":4},"sortOrder":4,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"64fd49a3-223b-460b-b312-d28d60a4e4af"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":4,"description":null,"rewardRange":{"id":"e18a1207-107c-4a42-979f-843e835d1ef0","p1MaxCents":250000,"p1MinCents":150000,"p2MaxCents":100000,"p2MinCents":70000,"p3MaxCents":30000,"p3MinCents":10000,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003e\u003cstrong\u003eFocus areas\u003c/strong\u003e - SQL Injections, RCE, auth bypasses, exfiltration of sensitive or PII data\u003c/p\u003e","rewardRangeData":{"1":{"min":1500,"max":2500},"2":{"min":700,"max":1000},"3":{"min":100,"max":300},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"1b74cf91-7504-41bd-acfb-5a0e01270fef","name":"Source code and supply chain","targets":[{"id":"80c149f3-1035-4dd3-b7df-48a1663e14f5","uri":"https://github.com/justeattakeaway","name":"github.com/justeattakeaway","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4d226d3b-f127-4198-8ea7-b2410431bc3d","sortOrder":0},"sortOrder":0,"tags":[{"id":"20f6988d-5b8c-41bb-9ca8-d9b271b7874d","name":"Github","targetId":"80c149f3-1035-4dd3-b7df-48a1663e14f5"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":4,"description":null,"rewardRange":{"id":"e18a1207-107c-4a42-979f-843e835d1ef0","p1MaxCents":250000,"p1MinCents":150000,"p2MaxCents":100000,"p2MinCents":70000,"p3MaxCents":30000,"p3MinCents":10000,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eWe accept reports related to supply chain security, GitHub Actions vulnerabilities, and credential leakage, but \u003cstrong\u003e\u003cem\u003enot code-level\u003c/em\u003e\u003c/strong\u003e vulnerabilities in repositories (such as XSS, SQL injection, etc.) unless they can be demonstrated to impact systems covered under \u0026quot;Business Platforms and APIs\u0026quot; scope.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eFocus Areas:\u003c/strong\u003e Leaked credentials with proven access to JET systems, supply chain attacks (dependency confusion, malicious injection, typosquatting) with verified JET infrastructure callbacks, active secrets in repositories/containers/configurations\u003c/p\u003e","rewardRangeData":{"1":{"min":1500,"max":2500},"2":{"min":700,"max":1000},"3":{"min":100,"max":300},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"e7e6a81c-cc70-4387-8078-5cc9641f3809","name":"Ouf of scope","targets":[{"id":"e54608d9-33c8-477a-987d-6a874346d5bb","uri":"","name":"*.business.just-eat.co.uk","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7574c3a0-f169-4d1a-9592-42272a281b90","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":5,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"75eb3f17-0489-4318-bf6f-cf0437307147","code":"justeattakeaway","state":"in_progress","endsAt":null,"bountyId":"5331b68f-52d4-4088-91ea-ccc6c05e440b","startsAt":"2019-04-30T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Hospitality","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/7e5a/a4bb/2b0e9195/5d8a532789835597667149ffeb712ff1_Screenshot-2021-09-30-at-14-19-09-Zeplin-Projects.png","logoBackgroundColor":"#FFF","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2019-04-30T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/justeattakeaway","changelogs":"/engagements/justeattakeaway/changelog","submissions":null,"announcements":"/engagements/justeattakeaway/announcements","hallOfFame":"/engagements/justeattakeaway/hall_of_fames","crowdstream":"/engagements/justeattakeaway/crowdstream"},"announcementsCount":34,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/justeattakeaway/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=justeattakeaway\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/justeattakeaway/engagement_subscribers","engagementChangelogsUrl":"/engagements/justeattakeaway/changelog","publishedAt":"2026-08-24T12:49:47.136Z","engagementChangelogUrl":"/engagements/justeattakeaway/changelog/c404df2a-d924-4789-99c8-3db04a5f4d86","createUserFeedbacksUrl":"/engagements/justeattakeaway/feedbacks","engagementCrowdstreamUrl":"/engagements/justeattakeaway/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}