{"id":"12e51944-fd89-4d71-bf45-6e5868fa4d9c","engagementId":"458aa2b5-eedb-4dd1-aac6-1f2eae153b40","data":{"brief":{"id":"ece2e627-3535-46ca-896c-e23741edd909","name":"Mattermost Public Bug Bounty Engagement ","tagline":"Mattermost is a leading collaboration platform for mission-critical work, serving national security, government, and critical infrastructure enterprises, offering secure, secure, and integrated collaboration experiences across various platforms.","description":"\u003cp\u003eMattermost is the leading collaboration platform for mission-critical work. We serve national security, government, and critical infrastructure enterprises, from the U.S. Department of Defense, to global tech giants, to utilities, banks and other vital services. We accelerate out-of-band incident response, DevSecOps workflows, mission operations, and self-sovereign collaboration to bolster the focus, adaptability, and resilience of the world’s most important organizations.\u003c/p\u003e\n\n\u003cp\u003eOur enterprise software and single-tenant SaaS platforms are built to meet the custom needs of rigorous and complex environments while offering a secure and unrivaled collaboration experience across web, desktop, and mobile with channel-based messaging, file sharing, audio calling, and screen share with integrated tooling, workflow automation, and AI assistance.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect, and Mattermost believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Mattermost not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Mattermost, you can report it to this program. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eAll of the targets are accessible via the public internet. For local setup, self-hosted installation options are available \u003ca href=\"https://github.com/mattermost/mattermost\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e or \u003ca href=\"https://mattermost.com/download/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eTo create an account: \u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eCreate an account at \u003ca href=\"https://customers.mattermost.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://customers.mattermost.com\u003c/a\u003e \u003c/li\u003e\n\u003cli\u003eOnce in the console, navigate the URL manually to \u003ca href=\"https://customers.mattermost.com/cloud\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://customers.mattermost.com/cloud\u003c/a\u003e and it will direct you you to the create workspace flow.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003ch4\u003eUser credentials created during self-signup don’t expire but invitation links sent by email expire after 48 hours and can only be used once. A Mattermost instance may be open to everyone to register or invitation-only.\u003c/h4\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRoles\u003c/h2\u003e\n\n\u003cp\u003eThere are multiple roles: Guest, Member, Channel Admin, Team Admin, Playbooks Admin, System Admin. There are also custom Admin roles, such as User Manager, System Manager, Viewer and Custom Groups Viewer. Please use the provided documentation and guidance of permissions-related reports. \u003c/p\u003e\n\n\u003cp\u003eRelated documentation:\u003cbr\u003e\nAll the roles come with a list of default permissions but per-role permissions can be modified. \u003cbr\u003e\n\u003ca href=\"https://docs.mattermost.com/collaborate/learn-about-roles.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAbout Roles\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://docs.mattermost.com/onboard/delegated-granular-administration.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eDelegated Granular Administration\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://docs.mattermost.com/onboard/advanced-permissions.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAdvanced Permissions\u003c/a\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eExclusions\u003c/h2\u003e\n\n\u003ch4\u003eIn scope but ineligible for bounty: *.mattermost.com\u003c/h4\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eMattermost does not consider the following to be eligible vulnerabilities:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny violation of our Program Rules\u003c/li\u003e\n\u003cli\u003eBrute force attacks. Example: Guessing a user's password\u003c/li\u003e\n\u003cli\u003eDisclosure of server or software version numbers\u003c/li\u003e\n\u003cli\u003eServer-side-request-forgery (SSRF) that requires system admin privileges, except on a cloud instance\u003c/li\u003e\n\u003cli\u003ePhishing using Unicode homoglyphs or RTLO characters\u003c/li\u003e\n\u003cli\u003eIssues with the SPF, DKIM or DMARC records (except from mattermost.com)\u003c/li\u003e\n\u003cli\u003eCSV/Formula Injection\u003c/li\u003e\n\u003cli\u003eAttacks requiring physical access to the victim's computer\u003c/li\u003e\n\u003cli\u003eAdversary-in-the-middle attacks\u003c/li\u003e\n\u003cli\u003eDistributed Denial of Service\u003c/li\u003e\n\u003cli\u003eContent spoofing\u003c/li\u003e\n\u003cli\u003eSocial Engineering, including phishing\u003c/li\u003e\n\u003cli\u003eEmail flooding\u003c/li\u003e\n\u003cli\u003eIssues related to XMLRPC\u003c/li\u003e\n\u003cli\u003eUnconfirmed reports from automated vulnerability scanners\u003c/li\u003e\n\u003cli\u003eAny issue in a mobile application that can only be exploited on a rooted or jailbroken device, that depends on debug access being enabled, or that depends on a vulnerability in the operating system\u003c/li\u003e\n\u003cli\u003eSelf-XSS without a reasonable attack scenario. In general, we accept these reports when there are a maximum of two steps required. For example, pasting a malicious payload into an input box and then clicking to preview it would be two steps\u003c/li\u003e\n\u003cli\u003eOpen Redirects without demonstrating additional security impact (such as stealing auth tokens)\u003c/li\u003e\n\u003cli\u003eReports exploiting the behavior of, or vulnerabilities in, outdated browsers\u003c/li\u003e\n\u003cli\u003eDenial of service attacks that only affect yourself. Example: A specially crafted request that causes you not to be able to login to your account\u003c/li\u003e\n\u003cli\u003eEnterprise Edition unlock attacks. Example: Modifying the source code to remove Enterprise Edition checks\u003c/li\u003e\n\u003cli\u003eReports about system users having scoped elevated permissions by default when there is a configuration option to restrict it, if needed\u003c/li\u003e\n\u003cli\u003eReports where a configuration option is available to mitigate the finding, if required\u003c/li\u003e\n\u003cli\u003ePublicly-released plugins \u003c/li\u003e\n\u003cli\u003eOther publicly-released plugins  - Plugins that Mattermost doesn't officially support. Accepted as informational only, we accept reports about important security issues with community plugins. Mattermost will handle contacting the plugin author and will provide guidance for the community member to implement a fix.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eKnown issues (not worth reporting):\u003c/h2\u003e\n\n\u003cp\u003eThe following vulnerability types are already known and won't be fixed. These issues will be closed as Not Applicable:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIt's possible for unauthenticated users to determine which email addresses do and don't have accounts\u003c/li\u003e\n\u003cli\u003eInformation disclosure related to cross-team isolation\u003c/li\u003e\n\u003cli\u003eOAuth applications don't yet support scopes and can do anything the authenticated user can do, including System Admin actions, regardless of impact. Only in scope when the action alters the delegation itself rather than acting on the user's behalf.\u003c/li\u003e\n\u003cli\u003eSince we are an open source company, we have a lot of public documents that might be considered confidential at other companies. For example, our JIRA instance is public\u003c/li\u003e\n\u003cli\u003eHyperlink Injection in the emails sent to the users\u003c/li\u003e\n\u003cli\u003eSystem Admins are allowed to perform any actions on the system\u003c/li\u003e\n\u003cli\u003eEXIF metadata not being stripped from images\u003c/li\u003e\n\u003cli\u003eRace conditions that lead to bypassing the limit\u003c/li\u003e\n\u003cli\u003eRemote code execution (RCE) in GitHub Actions via workflow_dispatch triggers, because these can only be initiated by users with repository write access (Mattermost employees), not external attack\u003c/li\u003e\n\u003cli\u003eApplication behavior resulting from sysadmin-manipulated HTTP requests that create unsupported permission states (e.g. removing read message permissions while maintaining channel membership)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eN-Day Policy\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 14 days have gone by\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on January 1st, we would consider it in-scope on January 15th\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":"\u003ch2\u003eSupport Documentation\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eMattermost source code: \u003ca href=\"https://github.com/mattermost/mattermost\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/mattermost\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eDesktop source code: \u003ca href=\"https://github.com/mattermost/desktop\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/desktop\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eMobile source code: \u003ca href=\"https://github.com/mattermost/mattermost-mobile\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/mattermost-mobile\u003c/a\u003e \u003c/li\u003e\n\u003cli\u003eBuilding, running, and testing Mattermost server locally: \u003ca href=\"https://developers.mattermost.com/contribute/developer-setup/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://developers.mattermost.com/contribute/developer-setup/\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eBuilding, running, and testing Mattermost Desktop locally:  \u003ca href=\"https://developers.mattermost.com/contribute/more-info/desktop/developer-setup/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://developers.mattermost.com/contribute/more-info/desktop/developer-setup/\u003c/a\u003e \u003c/li\u003e\n\u003cli\u003eBuilding, running, and testing Mattermost Mobile locally:  \u003ca href=\"https://developers.mattermost.com/contribute/more-info/mobile/developer-setup/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://developers.mattermost.com/contribute/more-info/mobile/developer-setup/\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eGeneral Mattermost documentation with explanations for all features, configuration options, roles etc: \u003ca href=\"https://docs.mattermost.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.mattermost.com/\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e"},"scope":[{"id":"4360d1ad-e977-49da-913c-a89caa34b167","name":"In Scope","targets":[{"id":"34e0f02b-c356-4a6b-b7eb-18166ee23fca","uri":"https://play.google.com/store/search?q=mattermost\u0026c=apps","name":"Mattermost Mobile Android","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"cf4afd48-17fc-4b35-84d0-1fc36695cf75","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"34e0f02b-c356-4a6b-b7eb-18166ee23fca"},{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"34e0f02b-c356-4a6b-b7eb-18166ee23fca"},{"id":"7cbdff60-9a91-41df-b802-486d21021b34","name":"ReactNative","targetId":"34e0f02b-c356-4a6b-b7eb-18166ee23fca"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"34e0f02b-c356-4a6b-b7eb-18166ee23fca"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"34e0f02b-c356-4a6b-b7eb-18166ee23fca"}],"recentChangeFlags":null},{"id":"50f2ea35-f1a2-4a51-92fe-cfa9a653cdcb","uri":"https://apps.apple.com/us/app/mattermost/id1257222717","name":"Mattermost Mobile iOS","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"abafa4d5-cb50-4e7f-926e-d11c243def8d","sortOrder":1},"sortOrder":1,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"50f2ea35-f1a2-4a51-92fe-cfa9a653cdcb"},{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"50f2ea35-f1a2-4a51-92fe-cfa9a653cdcb"},{"id":"7cbdff60-9a91-41df-b802-486d21021b34","name":"ReactNative","targetId":"50f2ea35-f1a2-4a51-92fe-cfa9a653cdcb"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"50f2ea35-f1a2-4a51-92fe-cfa9a653cdcb"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"50f2ea35-f1a2-4a51-92fe-cfa9a653cdcb"}],"recentChangeFlags":null},{"id":"056fb20b-1a85-4147-a57e-f766df1a09b1","uri":"https://mattermost.com/apps/","name":"Mattermost Desktop Apps","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"558250be-2803-48ce-be3a-b58acefd60b8","sortOrder":2},"sortOrder":2,"tags":[{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"056fb20b-1a85-4147-a57e-f766df1a09b1"},{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"056fb20b-1a85-4147-a57e-f766df1a09b1"},{"id":"47f8649b-7612-4d6d-bb41-c0078e628292","name":"Electron","targetId":"056fb20b-1a85-4147-a57e-f766df1a09b1"},{"id":"9c63a0f4-0db6-40da-85f0-65d0aa72bfbe","name":"Windows","targetId":"056fb20b-1a85-4147-a57e-f766df1a09b1"},{"id":"c5df6ad0-33b4-40ac-b6dd-8d4038997d40","name":"macOS","targetId":"056fb20b-1a85-4147-a57e-f766df1a09b1"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"056fb20b-1a85-4147-a57e-f766df1a09b1"},{"id":"fc8162a2-8e37-4a27-8cbd-3b40e7799f4e","name":"Desktop Application Testing","targetId":"056fb20b-1a85-4147-a57e-f766df1a09b1"}],"recentChangeFlags":null},{"id":"a6f9f74b-e3df-42e1-993d-d5031abf1c75","uri":"https://bugcrowd-*your-own-instance*.cloud.mattermost.com/","name":"https://bugcrowd-*your-own-instance*.cloud.mattermost.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"feff9a29-2948-42bf-9b5f-648fd320f4bd","sortOrder":3},"sortOrder":3,"tags":[{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"a6f9f74b-e3df-42e1-993d-d5031abf1c75"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"a6f9f74b-e3df-42e1-993d-d5031abf1c75"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"a6f9f74b-e3df-42e1-993d-d5031abf1c75"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"a6f9f74b-e3df-42e1-993d-d5031abf1c75"}],"recentChangeFlags":null},{"id":"509b7303-0082-405d-b7f4-12c99e65d627","uri":"https://github.com/mattermost/mattermost-plugin-jira ","name":"Mattermost Jira Plugin","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"056f603b-fbd1-4eb8-aa31-659b477610cb","sortOrder":4},"sortOrder":4,"tags":[{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"509b7303-0082-405d-b7f4-12c99e65d627"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"509b7303-0082-405d-b7f4-12c99e65d627"}],"recentChangeFlags":null},{"id":"790fea70-2623-4456-802f-d1f86f6f659b","uri":"https://github.com/mattermost/mattermost-plugin-zoom","name":"Mattermost Zoom Plugin","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d03d5c26-9820-414c-a704-4e489b4f75f7","sortOrder":5},"sortOrder":5,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"790fea70-2623-4456-802f-d1f86f6f659b"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"790fea70-2623-4456-802f-d1f86f6f659b"}],"recentChangeFlags":null},{"id":"7b85a687-09bc-4530-8d7e-d427e373ff33","uri":"https://github.com/mattermost/mattermost-plugin-github","name":"Mattermost Github Plugin","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5fd45531-26c1-4db1-9e45-777e6f8e2261","sortOrder":6},"sortOrder":6,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"7b85a687-09bc-4530-8d7e-d427e373ff33"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"7b85a687-09bc-4530-8d7e-d427e373ff33"}],"recentChangeFlags":null},{"id":"89617f96-b259-4cf8-a8a9-880d2bb8dc58","uri":"https://github.com/mattermost/mattermost-plugin-gitlab","name":"Mattermost Gitlab Plugin","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3abdef5e-8f67-4edd-8f0a-6dce88da2cdb","sortOrder":7},"sortOrder":7,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"89617f96-b259-4cf8-a8a9-880d2bb8dc58"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"89617f96-b259-4cf8-a8a9-880d2bb8dc58"}],"recentChangeFlags":null},{"id":"5f6d2682-39da-4b90-ac41-1412a63522c2","uri":"https://github.com/mattermost/mattermost-plugin-calls","name":"Mattermost Calls Plugin","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f8a097ba-f671-418e-ac98-99def1b095e6","sortOrder":8},"sortOrder":8,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"5f6d2682-39da-4b90-ac41-1412a63522c2"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"5f6d2682-39da-4b90-ac41-1412a63522c2"}],"recentChangeFlags":null},{"id":"0a226879-40e9-445d-9d6c-74574d2e3fd7","uri":"https://github.com/mattermost/mattermost-plugin-playbooks","name":"Mattermost Playbooks Plugin","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6d594b7a-0408-4f1f-b0f7-147d24727292","sortOrder":9},"sortOrder":9,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"0a226879-40e9-445d-9d6c-74574d2e3fd7"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"0a226879-40e9-445d-9d6c-74574d2e3fd7"}],"recentChangeFlags":null},{"id":"262b902d-d6e4-403a-9e46-11ec2eda5d42","uri":"https://github.com/mattermost/mattermost-plugin-boards","name":"Mattermost Boards Plugin","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b5b7eac8-6c7f-4276-8ce6-72b70c0a4466","sortOrder":10},"sortOrder":10,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"262b902d-d6e4-403a-9e46-11ec2eda5d42"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"262b902d-d6e4-403a-9e46-11ec2eda5d42"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"262b902d-d6e4-403a-9e46-11ec2eda5d42"}],"recentChangeFlags":null},{"id":"33206901-cb23-468e-ae13-397ba31bf3a8","uri":"https://github.com/mattermost/mattermost-plugin-ai","name":"Mattermost Copilot Plugin","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0f395b28-b77a-49a7-83b2-ff9e4074b2d6","sortOrder":11},"sortOrder":11,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"33206901-cb23-468e-ae13-397ba31bf3a8"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"33206901-cb23-468e-ae13-397ba31bf3a8"}],"recentChangeFlags":null},{"id":"3821be45-b675-4ed5-b81d-8cf433fc2f9b","uri":"https://github.com/mattermost/mattermost-plugin-mscalendar","name":"Mattermost Microsoft Calendar Plugin","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2abacc19-16ca-4871-9849-0442acad7696","sortOrder":12},"sortOrder":12,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"3821be45-b675-4ed5-b81d-8cf433fc2f9b"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"3821be45-b675-4ed5-b81d-8cf433fc2f9b"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"3821be45-b675-4ed5-b81d-8cf433fc2f9b"}],"recentChangeFlags":null},{"id":"a13c9d27-8716-4e3b-bd1a-4b92d3f43064","uri":"https://github.com/mattermost/mattermost-plugin-msteams-meetings","name":"Mattermost Plugin for Microsoft Teams Meetings","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7b43a678-c771-48e9-81c2-ebf140b3dbac","sortOrder":13},"sortOrder":13,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"a13c9d27-8716-4e3b-bd1a-4b92d3f43064"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"a13c9d27-8716-4e3b-bd1a-4b92d3f43064"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"a13c9d27-8716-4e3b-bd1a-4b92d3f43064"}],"recentChangeFlags":null},{"id":"e29f39bc-02a5-4490-8e50-bb6f67297828","uri":"https://github.com/mattermost/mattermost-plugin-confluence","name":"Mattermost Confluence Plugin","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5a170179-649e-469d-b0ba-e3ab5a389573","sortOrder":14},"sortOrder":14,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"e29f39bc-02a5-4490-8e50-bb6f67297828"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"e29f39bc-02a5-4490-8e50-bb6f67297828"}],"recentChangeFlags":null},{"id":"a14c016f-475e-4f94-8c00-4abcf90db5be","uri":"https://github.com/mattermost/mattermost-plugin-msteams","name":"Mattermost MSTeams Plugin","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3e15bb1d-4d48-40b2-bf6d-974954b89877","sortOrder":15},"sortOrder":15,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"a14c016f-475e-4f94-8c00-4abcf90db5be"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"a14c016f-475e-4f94-8c00-4abcf90db5be"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"50f24650-b1bc-49e4-b9ba-03aa05cf458a","p1MaxCents":200000,"p1MinCents":200000,"p2MaxCents":75000,"p2MinCents":75000,"p3MaxCents":30000,"p3MinCents":30000,"p4MaxCents":15000,"p4MinCents":15000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eMattermost is an open-source collaboration and messaging platform designed for secure and efficient team communications. It allows team members to communicate in real-time through channels, direct messages, and group chats. In addition to messaging, Mattermost includes Playbooks, which are customizable workflows that help teams standardize and automate processes, and Calls, a feature for audio communication directly within the platform.  Additionally, it integrates with various tools and services via plugins (Github, GitLab, Zoom, Jira etc.) to streamline workflows. Mattermost offers both self-hosted and cloud deployment options. The target consists of a backend, a webapp, a desktop app and mobile apps (iOS \u0026amp; Android).\u003c/p\u003e\n\n\u003ch4\u003eA free instance can be created by signing up at \u003ca href=\"https://customers.mattermost.com/cloud/signup\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://customers.mattermost.com/cloud/signup\u003c/a\u003e\u003c/h4\u003e\n\n\u003cp\u003eOtherwise, the target can be installed locally with the following ways:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eFrom source code: \u003ca href=\"https://github.com/mattermost/mattermost\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/mattermost\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eOther installation options: \u003ca href=\"https://mattermost.com/download/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://mattermost.com/download/\u003c/a\u003e \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMattermost Jira Plugin - Two-way integration between Mattermost and Jira. Supports Jira to Mattermost notifications  (channel subscriptions and personal notifications) and managing Jira issues in Mattermost (create issue, attaching messages to Jira issues, transition Jira issues, assign Jira issues)\u003cbr\u003e\nSource code: \u003ca href=\"https://github.com/mattermost/mattermost-plugin-jira\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/mattermost-plugin-jira\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMattermost Zoom Plugin - Allows team members to initiate a Zoom meeting with a single click. All participants in a channel can easily join the Zoom meeting and the shared link is updated when the meeting is over.\u003cbr\u003e\nSource code: \u003ca href=\"https://github.com/mattermost/mattermost-plugin-zoom\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/mattermost-plugin-zoom\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMattermost GitHub Plugin - Two-way integration between Mattermost and GitLab. Offers real-time updates on commits, pull requests, issues and  the ability to create GH issues from within Mattermost\u003cbr\u003e\nSource code: \u003ca href=\"https://github.com/mattermost/mattermost-plugin-github\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/mattermost-plugin-github\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMattermost GitLab Plugin - Two-way integration between Mattermost and GitLab.  Offers real-time updates and notifications on new and closed merge requests, new and closed issues, and tag creation events.\u003cbr\u003e\nSource code: \u003ca href=\"https://github.com/mattermost/mattermost-plugin-gitlab\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/mattermost-plugin-gitlab\u003c/a\u003e \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMattermost Calls Plugin - This really part of the primary target but it’s developed as a plugin. It enables voice calling and screen sharing functionality in Mattermost channels.\u003cbr\u003e\nSource code: \u003ca href=\"https://github.com/mattermost/mattermost-plugin-calls\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/mattermost-plugin-calls\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMattermost Playbooks Plugin - This is also part of the primary target but is developed as a plugin. Playbooks in Mattermost provide structure, monitoring, and automation for team-based processes. They use configurable checklists to guide teams toward specific outcomes, triggering tasks based on keywords or actions. Playbooks can include automated/manual tasks, status updates, workflow dashboards, and retrospective reviews as part of their execution and completion.\u003cbr\u003e\nSource code: \u003ca href=\"https://github.com/mattermost/mattermost-plugin-playbooks\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/mattermost-plugin-playbooks\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMattermost Boards plugin - A project management tool within the Mattermost platform that allows teams to organize, track, and collaborate on tasks visually, using a board-style layout similar to kanban.\u003cbr\u003e\nSource code: \u003ca href=\"https://github.com/mattermost/mattermost-plugin-boards\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/mattermost-plugin-boards\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMattermost Copilot plugin -  AI-powered tool that assists users by generating insights, summaries, and automated responses\u003cbr\u003e\nSource code: \u003ca href=\"https://github.com/mattermost/mattermost-plugin-ai\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/mattermost-plugin-ai\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMattermost Microsoft Calendar Plugin -  Two-way integration between Mattermost and Microsoft Outlook Calendar.\u003cbr\u003e\nSource code: \u003ca href=\"https://github.com/mattermost/mattermost-plugin-mscalendar\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/mattermost-plugin-mscalendar\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMattermost Plugin for Microsoft Teams Meetings - Enables users to schedule, join, and manage Microsoft Teams meetings directly from the Mattermost platform\u003cbr\u003e\nSource code: \u003ca href=\"https://github.com/mattermost/mattermost-plugin-msteams-meetings\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/mattermost-plugin-msteams-meetings\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMattermost MSTeams Plugin - Enables forwarding real-time chat notifications from Microsoft Teams to Mattermost.\u003cbr\u003e\nSource code: \u003ca href=\"https://github.com/mattermost/mattermost-plugin-msteams\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/mattermost-plugin-msteams\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMattermost Plugin for Confluence - Integration from Confluence to Mattermost, delivering real-time updates on page and space activity directly into channels, with simple in-channel subscription management.\u003cbr\u003e\nSource code: \u003ca href=\"https://github.com/mattermost/mattermost-plugin-confluence\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/mattermost/mattermost-plugin-confluence\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":2000,"max":2000},"2":{"min":750,"max":750},"3":{"min":300,"max":300},"4":{"min":150,"max":150},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"84b1fd47-a382-49b5-bc9a-8370f52fccf7","name":"Out of Scope","targets":[{"id":"1085eec3-99d7-4e93-a535-f12aad7e10b1","uri":"","name":"about.mattermost.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"42ac1a2d-ab8c-4bf0-b1e5-29a472351d26","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"7a0f233c-163b-4123-a300-e8fff015038f","uri":"","name":"integrations.mattermost.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"88b2585c-c22f-4ebe-b394-779cbe1cbb36","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"a328ebd1-8bf8-42e7-b212-2fdb3a96e5ad","uri":"","name":"docs.mattermost.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"38ade468-71c7-4366-adc7-a9f28eae2fc9","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"ecb78307-ad1e-4707-8d48-cd36dc51cfc0","uri":"","name":"academy.mattermost.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"af77735f-69f0-4c21-9396-d7fcdfff1781","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"212027b1-c5e1-4357-9fd5-16db9d5dac4d","uri":"","name":"developers.mattermost.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"97407939-f500-4d53-9ba0-25b34de67ef3","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null},{"id":"8753d28d-153e-4b23-91bb-204588f67e43","uri":"","name":"forum.mattermost.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d5df8269-8dc4-4f9f-956a-bcc6dd6f0df0","sortOrder":5},"sortOrder":5,"tags":null,"recentChangeFlags":null},{"id":"f817db39-3ad2-4089-8307-9435526727a1","uri":"","name":"mattermost.com (the main website)","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7c3b73a2-73ae-4f75-bdcc-07ec612dfa06","sortOrder":6},"sortOrder":6,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"458aa2b5-eedb-4dd1-aac6-1f2eae153b40","code":"mattermost-mbb-public","state":"in_progress","endsAt":null,"bountyId":"8f20dbe4-5106-41db-984b-63232015e279","startsAt":"2024-11-06T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/f6f7/cc22/4766e99e/be474b0a3bf26637eaaff2aff7e65274_mattermost_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-11-06T18:00:00.112Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/mattermost-mbb-public","changelogs":"/engagements/mattermost-mbb-public/changelog","submissions":null,"announcements":"/engagements/mattermost-mbb-public/announcements","hallOfFame":"/engagements/mattermost-mbb-public/hall_of_fames","crowdstream":"/engagements/mattermost-mbb-public/crowdstream"},"announcementsCount":3,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/mattermost-mbb-public/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=mattermost-mbb-public\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/mattermost-mbb-public/engagement_subscribers","engagementChangelogsUrl":"/engagements/mattermost-mbb-public/changelog","publishedAt":"2026-09-04T15:33:01.896Z","engagementChangelogUrl":"/engagements/mattermost-mbb-public/changelog/12e51944-fd89-4d71-bf45-6e5868fa4d9c","createUserFeedbacksUrl":"/engagements/mattermost-mbb-public/feedbacks","engagementCrowdstreamUrl":"/engagements/mattermost-mbb-public/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}