{"id":"a7dce790-95c8-4581-a8f5-57c71d0b9e5b","engagementId":"09159d9d-fad3-4884-8b71-1de2084c5cd7","data":{"brief":{"id":"1c35ef50-8ace-4bb5-bf6a-53850f96ee6f","name":"State of Maryland Vulnerability Disclosure Program","tagline":"A centralized VDP for the State of Maryland, including State, Local, Tribal, and Territorial government entities. Got a bug? Drop it here.","description":"\u003ch2\u003eIntroduction\u003c/h2\u003e\n\n\u003cp\u003eThe State of Maryland Vulnerability Disclosure Program is a centralized, statewide initiative managed by the Maryland Department of Information Technology (DoIT). It enables coordinated vulnerability reporting and security engagement for all State, Local, Tribal, and Territorial government entities. DoIT delivers critical technology services that help keep Maryland’s digital infrastructure secure, reliable, and effective—empowering safe and accessible services for all residents.\u003c/p\u003e\n\n\u003cp\u003eMaryland is committed to working with the security research community to improve the security of our systems and data. This program offers a secure, authorized channel for responsible disclosure of vulnerabilities. By identifying and resolving issues proactively, we aim to reduce risk, strengthen public trust, and safeguard essential services.\u003c/p\u003e\n\n\u003cp\u003eThank you for your contribution to responsible security research. We look forward to working together to protect Maryland’s digital future.\u003c/p\u003e\n\n\u003cp\u003eGood luck, and happy hunting!\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings / Rewards\u003c/h2\u003e\n\n\u003cp\u003eThis engagement uses the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e as the baseline for prioritizing and rating submissions. However, priorities may be adjusted based on factors such as exploitability and business impact. If a vulnerability is downgraded, a detailed explanation will be provided, and researchers will have the opportunity to appeal.\u003c/p\u003e","industryTagId":"2a38890b-c88e-4bc0-8db0-02059f3fafe6","targetsOverview":"\u003cp\u003eAll systems and services associated with the domains explicitly listed in the Scope section are in scope. Subdomains are also considered in scope unless specifically excluded. Additionally, any Maryland government site that links directly to this policy is considered in scope.\u003c/p\u003e\n\n\u003cp\u003eIf a system is not listed but appears relevant or vulnerable, please contact us through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before proceeding. If in doubt, reach out before testing.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRules of Engagement\u003c/h2\u003e\n\n\u003ch3\u003eSecurity Researchers Shall\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eCease testing and notify us immediately upon discovery of a vulnerability.\u003c/li\u003e\n\u003cli\u003eCease testing and notify us immediately upon exposure or access of nonpublic or sensitive data.\u003c/li\u003e\n\u003cli\u003ePurge any stored State of Maryland nonpublic data after reporting a vulnerability.\u003c/li\u003e\n\u003cli\u003eLimit system and application access and data viewing to only what is strictly necessary to confirm the presence of a vulnerability.\u003c/li\u003e\n\u003cli\u003eNot retain, alter, destroy, render inaccessible, or share any data encountered during testing.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eUnauthorized Activity\u003c/h3\u003e\n\n\u003cp\u003eTo protect systems, users, and data, the following are strictly prohibited:\u003c/p\u003e\n\n\u003ch4\u003eHarmful or Disruptive Behavior\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eDo not conduct activity that could be reasonably expected to degrade, disrupt, or damage State services.\u003c/li\u003e\n\u003cli\u003eThis includes, but is not limited to: Denial of Service (DoS/DDoS), mass automated testing, rate limit abuse, email bombing, or service degradation testing.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eSocial Engineering and Deception\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eDo not use any social engineering tactics such as phishing, smishing, pretexting, or impersonation.\u003c/li\u003e\n\u003cli\u003eDo not interact with or attempt to deceive State of Maryland employees or users.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eUnauthorized Access Methods\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eDo not attempt to gain physical access to or otherwise test State of Maryland buildings or facilities.\u003c/li\u003e\n\u003cli\u003eDo not use attacker-in-the-middle (AITM) methods or network sniffing.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003ePassword and Credential Attacks\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eDo not perform brute force attacks, credential stuffing, password spraying, or repeated login attempts against other users' accounts.\u003c/li\u003e\n\u003cli\u003eDo not use credentials obtained from third-party breaches or public leaks—even if publicly available. See \"Leaked or Exposed Credentials\" below.\u003c/li\u003e\n\u003cli\u003eIf you encounter exposed or leaked credentials, please report them as described in the Leaked or Exposed Credentials section.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eUnsafe Changes or Interference\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eDo not modify or delete data in accounts or systems you do not own.\u003c/li\u003e\n\u003cli\u003eDo not intentionally alter system states, configurations, or files beyond what’s necessary to confirm the presence of a vulnerability. Do not intentionally weaken the security of an asset being tested.\u003c/li\u003e\n\u003cli\u003eDo not install persistent access mechanisms such as backdoors or shells.\u003c/li\u003e\n\u003cli\u003eDo not attempt to \"pivot\" to additional State of Maryland assets or further exploit an asset after confirming the presence of a vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cp\u003eWe will not accept reports for:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e \u003cstrong\u003eunless they are part of a chained exploit that demonstrates real-world impact\u003c/strong\u003e\n\u003c/li\u003e\n\u003cli\u003ePolicy violations without an accompanying technical vulnerability\u003c/li\u003e\n\u003cli\u003eIssues with no clear, demonstrable risk\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eN-day / Third-party 0-day Practice\u003c/h3\u003e\n\n\u003cp\u003eWe recognize that the security research community is often among the first to identify and validate newly disclosed N-Day vulnerabilities. These contributions are valuable and encouraged under this program.\u003c/p\u003e\n\n\u003cp\u003eWe do not impose an embargo period on N-Day submissions. Researchers may submit relevant findings as soon as public disclosure occurs.\u003c/p\u003e\n\n\u003cp\u003eHowever, in the case of large-scale or high-impact N-Day vulnerabilities (e.g., Log4Shell, ProxyShell, MOVEit), we may expand our triage window and require more rigorous evidence. Submissions must demonstrate real, actionable impact, not just version fingerprinting or automated scan results.\u003c/p\u003e\n\n\u003cp\u003eAcceptable evidence may include:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eProof-of-concept (PoC) exploit demonstrating the vulnerability in action\u003c/li\u003e\n\u003cli\u003eAccess to sensitive functionality or data as a result of the issue\u003c/li\u003e\n\u003cli\u003eAuthenticated or verifiable server responses that confirm exploitability\u003c/li\u003e\n\u003cli\u003eScreenshots or logs confirming unintended behavior\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eVulnerabilities in third-party systems not managed by the State of Maryland should be reported directly to the vendor, in accordance with their own disclosure policies.\u003c/p\u003e\n\n\u003ch2\u003eLeaked or Exposed Credentials\u003c/h2\u003e\n\n\u003cp\u003eIf you discover exposed credentials—whether through dark web sources, public leaks, or within testing—you are encouraged to report them.\u003c/p\u003e\n\n\u003cp\u003eDo not use or attempt to authenticate with credentials that are not yours. Simply report their presence and context.\u003c/p\u003e\n\n\u003ch2\u003eAuthorization and Good Faith\u003c/h2\u003e\n\n\u003cp\u003eMaryland recognizes the importance of external security researchers in identifying and reporting vulnerabilities that could impact our systems, constituents, and data. We are committed to working with the security community to strengthen our defenses and appreciate responsible disclosures made in good faith. As such, the VDP will include a Safe Harbor for external security researchers who act in good faith.\u003c/p\u003e\n\n\u003cp\u003eAll research under this VDP must be conducted in good faith. \"Good faith” means security research conducted with the intent to follow the VDP without any malicious motive and solely for the purpose of testing or investigating a security flaw or vulnerability and disclosing those findings in alignment with the VDP. The security researcher’s actions should be consistent with an attempt to improve security and to avoid doing harm, either by unwarranted invasions of privacy or causing damage to property.\u003c/p\u003e\n\n\u003cp\u003eIf Department of Information Technology (DoIT) and Office of Security Management (OSM) determine that research is conducted in good faith, it will consider that security research to be authorized, will work with the external security researcher(s) to understand and resolve reports quickly, and will not recommend legal action related to the security research.\u003c/p\u003e\n\n\u003cp\u003eShould legal action be initiated by a third party against the security researcher for research conducted in accordance with the VDP, DoIT and OSM will make this authorization known. External security researchers must comply with all applicable Federal, State, and local laws in connection with the security research activities or other participation in the VDP.\u003c/p\u003e\n\n\u003cp\u003eBy participating in our VDP, external security researchers acknowledge and agree to the VDP’s terms. If there are questions about the scope or interpretation of this Safe Harbor, we encourage external security researchers to seek clarification before conducting testing.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"f0e2cf84-bf6a-438b-96b0-04877d4aca75","name":"In Scope","targets":[{"id":"64573744-cc9f-49b8-8695-66e9646015a6","uri":"","name":"*.maryland.gov","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"746bb920-23b1-4c91-b1a6-d70050550dc3","sortOrder":1},"sortOrder":1,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"64573744-cc9f-49b8-8695-66e9646015a6"}],"recentChangeFlags":null},{"id":"32249143-95e2-4e0c-9228-f90a6342bdb5","uri":"","name":"*.md.gov","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ddccd328-dd57-48fb-980d-c985bab2df2b","sortOrder":2},"sortOrder":2,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"32249143-95e2-4e0c-9228-f90a6342bdb5"}],"recentChangeFlags":null},{"id":"0f529290-5d9b-4a29-97da-e80b2fde7d6a","uri":"","name":"*.state.md.us","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4acf2c65-9384-4c8f-9dcd-eda49164bf22","sortOrder":3},"sortOrder":3,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"0f529290-5d9b-4a29-97da-e80b2fde7d6a"}],"recentChangeFlags":null},{"id":"2e12cdc1-1546-4cff-8c35-3c3f69c38c86","uri":"","name":"networkMaryland","category":"network","ipAddress":"167.102.0.0/16","description":null,"engagementBriefTargetGroupTarget":{"id":"9a49bb3a-3e14-4af9-874f-7cdb24e4876b","sortOrder":4},"sortOrder":4,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"2e12cdc1-1546-4cff-8c35-3c3f69c38c86"}],"recentChangeFlags":null},{"id":"c6633430-85c8-45e7-b74e-26a8a6026ff1","uri":null,"name":"*.aacounty.org","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5f1ae577-4288-4b44-bfe4-a5a069f38ce0","sortOrder":4},"sortOrder":4,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"c6633430-85c8-45e7-b74e-26a8a6026ff1"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"09159d9d-fad3-4884-8b71-1de2084c5cd7","code":"maryland-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"7ce95a76-461d-4034-a255-02fe5609451e","startsAt":"2025-09-09T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Government","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/d24b/02b3/139e28e5/3791222b31813868457b9dd5a2f1111b_maryland_department_of_information_technology_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-10-21T15:00:20.491Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/maryland-vdp-pro","changelogs":"/engagements/maryland-vdp-pro/changelog","submissions":null,"announcements":"/engagements/maryland-vdp-pro/announcements","hallOfFame":"/engagements/maryland-vdp-pro/hall_of_fames","crowdstream":"/engagements/maryland-vdp-pro/crowdstream"},"announcementsCount":8,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/maryland-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=maryland-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/maryland-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/maryland-vdp-pro/changelog","publishedAt":"2026-09-01T15:06:54.093Z","engagementChangelogUrl":"/engagements/maryland-vdp-pro/changelog/a7dce790-95c8-4581-a8f5-57c71d0b9e5b","createUserFeedbacksUrl":"/engagements/maryland-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/maryland-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}