{"id":"111f077e-65a4-4bd8-9b67-940c7d2ea20f","engagementId":"63d6c8b7-f44a-48b5-b3cf-5324066689db","data":{"brief":{"id":"2cc59da5-6f15-4a9d-95a7-622c9d078d1e","name":"National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program","tagline":"Explore the universe and discover our home planet with the official NASA disclosure program! ","description":"\u003ch2\u003eTarget Information\u003c/h2\u003e\n\n\u003cp\u003eThe NASA Mission is to drive advances in science, technology, aeronautics, and space exploration to enhance knowledge, education, innovation, economic vitality and stewardship of the Earth. A great deal of NASA work leverages information technology to capture, interpret, and appropriately share scientific knowledge in the furtherance of its Missions and Programs. NASA is committed to protecting the confidentiality (where appropriate), integrity, and availability of its information and information systems.\u003c/p\u003e\n\n\u003cp\u003eNASA recognizes that external vulnerabilities can be discovered by anyone at any time and has issued this policy in order to provide clear guidelines to security researchers so that they feel comfortable reporting vulnerabilities they have discovered in good faith.\u003c/p\u003e\n\n\u003cp\u003eThis vulnerability disclosure policy facilitates NASA’s awareness of otherwise unknown vulnerabilities. This policy is intended to give security researchers clear guidelines for conducting vulnerability discovery and disclosure activities to help NASA meet its objectives, and to convey how to submit discovered vulnerabilities to NASA.\u003c/p\u003e\n\n\u003cp\u003eThis policy describes\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhat systems and types of research are covered under this policy\u003c/li\u003e\n\u003cli\u003eGeneral guidelines for demonstrating good faith\u003c/li\u003e\n\u003cli\u003eHow to submit vulnerability reports\u003c/li\u003e\n\u003cli\u003eWhat to expect following a vulnerability report\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eLetters of Recognition (LOR) Criteria\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNot all submitted reports qualify for an LOR.\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReports flagged as duplicates or identified as known issues do not qualify for an LOR.\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eLORs are awarded exclusively for P1-P4 rated reports that have been validated, accepted, and confirmed as fixed.\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"2a38890b-c88e-4bc0-8db0-02059f3fafe6","targetsOverview":"\u003cp\u003eTesting is strictly authorized only on the listed target and its subdomains within the defined scope. Any domains or subdomains outside of the domains as  listed in Scope are out of scope and not eligible for testing. Services that are not explicitly listed above are not authorized for testing. You can expect to receive an acknowledgment of your report within three business days of submission.\u003cbr\u003e\nPlease keep your vulnerability reports current by sending us any new information as it becomes available. We may share your vulnerability reports with CISA, and any affected vendors or open-source projects.\u003c/p\u003e\n\n\u003cp\u003eThe following subsections define the systems and types of testing that are and are not in scope of this policy. If it is unclear whether a system or type of testing is or is not in scope, please contact \u003ca href=\"mailto:Agency-DL-VAMP-VDP@mail.nasa.gov\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAgency-DL-VAMP-VDP@mail.nasa.gov\u003c/a\u003e before commencing any research activities.\u003c/p\u003e\n\n\u003ch1\u003eSystems\u003c/h1\u003e\n\n\u003cp\u003e\u003cstrong\u003eThis policy applies to all NASA-managed systems that are accessible from the Internet. This includes the registered domain names that are provided above.\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eNASA internal-only services are not in scope and are not authorized for testing. Additionally, vulnerabilities found in non-federal systems from our vendors and contractors fall outside of this policy’s scope and should be reported directly to the vendor or contractor according to their disclosure policy (if any).\u003c/p\u003e\n\n\u003cp\u003eNon-public NASA data is not authorized to reside on public third-party services. Although the third-party services themselves are not in scope, please report these data issues to NASA. The following types of non-public data are particularly sensitive, and warrant immediate reporting:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSensitive personally identifiable information (e.g., social security numbers)\u003c/li\u003e\n\u003cli\u003eFinancial information (e.g., credit card or bank account numbers)\u003c/li\u003e\n\u003cli\u003eProprietary information or trade secrets of companies of any party; and\u003c/li\u003e\n\u003cli\u003eDocuments with sensitivity markings (e.g., \"Top Secret\" or \"ITAR/EAR\")\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eTypes of Testing\u003c/h3\u003e\n\n\u003cp\u003eThe following test types are not authorized:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSocial engineering-based attacks (e.g., getting a user to click an attacker-controlled link)\u003c/li\u003e\n\u003cli\u003eDenial of Service, Rate Limiting, or Spamming issues (e.g., layer 7 DOS attacks, Slowloris, etc.)\u003c/li\u003e\n\u003cli\u003eClickjacking on pages with no sensitive actions\u003c/li\u003e\n\u003cli\u003eAny reports with the endpoint /wp-json/wp/v2/users\u003c/li\u003e\n\u003cli\u003eAny reports with the endpoint xmlrpc.php \u003c/li\u003e\n\u003cli\u003eAttacks requiring physical access to a user’s device\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without a working proof of concept.\u003c/li\u003e\n\u003cli\u003eContent spoofing or text injection\u003c/li\u003e\n\u003cli\u003eReports from automated tools or scans without accompanying demonstration of exploitability\u003c/li\u003e\n\u003cli\u003eSoftware version disclosure without accompanying demonstration of exploitability\u003c/li\u003e\n\u003cli\u003eUse of a known-vulnerable library without evidence of exploitability\u003c/li\u003e\n\u003cli\u003eMissing best practices. (Missing security headers, missing captcha, insecure certs)\u003c/li\u003e\n\u003cli\u003eInsecure SSL or TLS issues (e.g., ciphers, certificates, etc.)\u003c/li\u003e\n\u003cli\u003eMissing security headers (e.g., HTTP Strict-Transport-Security (HSTS), Content Security Policy (CSP), etc.) that do not lead directly to a vulnerability.\u003c/li\u003e\n\u003cli\u003ePresence of the “autocomplete” attribute on web forms\u003c/li\u003e\n\u003cli\u003eHost header injections unless you can show how they can lead to stealing user data\u003c/li\u003e\n\u003cli\u003eInsecure cookie settings for non-sensitive cookies\u003c/li\u003e\n\u003cli\u003eDirectory Listing\u003c/li\u003e\n\u003cli\u003eVulnerabilities affecting users of outdated browsers or platforms\u003c/li\u003e\n\u003cli\u003eIssues related to descriptive or verbose error messages\u003c/li\u003e\n\u003cli\u003eAny other non-technical vulnerability testing\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eGuidelines\u003c/h1\u003e\n\n\u003cp\u003eNASA requests that security researchers make every effort to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAvoid impacting the availability of production systems. If a non‑production or public test environment is available, all testing must be performed exclusively in that environment. Example: Test in test.gcn.nasa.gov NOT in gcn.nasa.gov\u003c/li\u003e\n\u003cli\u003eNotify NASA via the methods described in the policy as soon as possible after the discovery of a potential security issue.\u003c/li\u003e\n\u003cli\u003e Keep all information about discovered vulnerabilities confidential until NASA approves the disclosure request. \u003c/li\u003e\n\u003cli\u003e Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction, modification, or exfiltration of NASA data.\u003c/li\u003e\n\u003cli\u003e Only use exploits to the extent necessary to confirm the presence of a vulnerability. Do not use an exploit to compromise or exfiltrate data, establish command line access and/or persistence, or leverage the exploit to “pivot” to other systems.\u003c/li\u003e\n\u003cli\u003e Once it is established that a vulnerability exists or any sensitive data is encountered (including personally identifiable information, financial information, proprietary information or trade secrets of any party), \u003cstrong\u003eyou must stop your test, NASA must be notified immediately, and details of the vulnerability or sensitive data shall not be disclosed to anyone else.\u003c/strong\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eNo compensation is available, other than NASA’s gratitude for your help in advancing the NASA Mission. By submitting a vulnerability report, you waive all claims to compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eAuthorization\u003c/h1\u003e\n\n\u003cp\u003eIf a security researcher makes a good faith effort to comply with this policy during security research, NASA will consider that research to be authorized, and will work with them to understand and resolve the issue quickly. In addition, NASA will not recommend or pursue legal action related to the research. Should legal action be initiated by a third party against a security researcher for activities that were conducted in accordance with this policy, NASA will make this authorization known.\u003c/p\u003e\n\n\u003ch1\u003eReporting a vulnerability\u003c/h1\u003e\n\n\u003cp\u003eThis reporting mechanism is not intended for use by NASA employees, contractors, and others with authorized IT access at NASA. NASA personnel should use NASA-internal IT support and reporting mechanisms rather than this program.\u003c/p\u003e\n\n\u003cp\u003eInformation submitted under this policy will be used for defensive purposes only – to mitigate or remediate vulnerabilities.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eWhat NASA would like to see in a report\u003c/h1\u003e\n\n\u003cp\u003eIn order to help us triage and prioritize submissions, NASA recommends that vulnerability reports:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDescribe the vulnerability, where it was discovered, and the potential impact of exploitation.\u003c/li\u003e\n\u003cli\u003eOffer a detailed description of the steps needed to reproduce the vulnerability (proof of concept scripts or screenshots are helpful).\u003c/li\u003e\n\u003cli\u003e Be in the English language, if possible.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003ePlease do not use this mechanism to report trivial system faults, such as typos or user interface errors not resulting in a vulnerability. NASA believes that public disclosure in the absence of a readily available mitigation will increase risk to NASA Missions. As a result, NASA requests that researchers refrain from sharing vulnerability reports with others for 90 days following the submission of the initial report, unless otherwise coordinated with NASA.\u003c/p\u003e\n\n\u003ch1\u003eWhat a security researcher can expect from NASA\u003c/h1\u003e\n\n\u003cp\u003eWhen a security researcher chooses to share their contact information with NASA, NASA is committed to coordinating a response with you as openly and as quickly as possible.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWithin three business days, NASA will acknowledge the receipt of a report.\u003c/li\u003e\n\u003cli\u003eTo the best of our ability, we will confirm the existence of the vulnerability to you and be as transparent as possible about what steps we are taking during the remediation process, including issues or challenges that may delay resolution.\u003c/li\u003e\n\u003cli\u003eWe will maintain an open dialogue to discuss issues.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"57654848-a656-417f-99b9-7f5797dbe5ac","name":"In Scope ","targets":[{"id":"27375195-22b0-4c01-a736-2650541aa3dd","uri":"https://www.nasa.gov","name":"https://nasa.gov","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a49ebc23-903b-4a5f-86f7-8c250d3026aa","sortOrder":0},"sortOrder":0,"tags":[{"id":"3585ef4a-cd09-429b-ad25-5777064e59c5","name":"Moment.js","targetId":"27375195-22b0-4c01-a736-2650541aa3dd"},{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"27375195-22b0-4c01-a736-2650541aa3dd"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"27375195-22b0-4c01-a736-2650541aa3dd"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"27375195-22b0-4c01-a736-2650541aa3dd"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"27375195-22b0-4c01-a736-2650541aa3dd"}],"recentChangeFlags":null},{"id":"02ca5ef6-31c7-4648-b287-8ec4dbccf381","uri":"https://usgeo.gov/","name":"https://usgeo.gov/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5e3d34d8-c22b-4f81-8266-e50fd25301c4","sortOrder":0},"sortOrder":0,"tags":[{"id":"3585ef4a-cd09-429b-ad25-5777064e59c5","name":"Moment.js","targetId":"02ca5ef6-31c7-4648-b287-8ec4dbccf381"},{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"02ca5ef6-31c7-4648-b287-8ec4dbccf381"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"02ca5ef6-31c7-4648-b287-8ec4dbccf381"}],"recentChangeFlags":null},{"id":"2309ef5e-2317-4f88-834a-1df3b395a8b2","uri":"https://globe.gov/","name":"https://globe.gov/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4dd1fbca-5c8d-4d72-9c13-64816c74156a","sortOrder":0},"sortOrder":0,"tags":[{"id":"3585ef4a-cd09-429b-ad25-5777064e59c5","name":"Moment.js","targetId":"2309ef5e-2317-4f88-834a-1df3b395a8b2"},{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"2309ef5e-2317-4f88-834a-1df3b395a8b2"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"2309ef5e-2317-4f88-834a-1df3b395a8b2"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"2309ef5e-2317-4f88-834a-1df3b395a8b2"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2309ef5e-2317-4f88-834a-1df3b395a8b2"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"63d6c8b7-f44a-48b5-b3cf-5324066689db","code":"nasa-vdp","state":"in_progress","endsAt":null,"bountyId":"ba51b94f-50b1-4137-9ece-14c29699c9eb","startsAt":"2023-06-01T12:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Government","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/e34e/ced8/462922dd/fe2d0bf28f7b56095470ca07d0421e95_1615217311496.jpeg","logoBackgroundColor":"#000000","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2023-06-01T12:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/nasa-vdp","changelogs":"/engagements/nasa-vdp/changelog","submissions":null,"announcements":"/engagements/nasa-vdp/announcements","hallOfFame":"/engagements/nasa-vdp/hall_of_fames","crowdstream":"/engagements/nasa-vdp/crowdstream"},"announcementsCount":7,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/nasa-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=nasa-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/nasa-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/nasa-vdp/changelog","publishedAt":"2026-05-01T20:24:52.269Z","engagementChangelogUrl":"/engagements/nasa-vdp/changelog/111f077e-65a4-4bd8-9b67-940c7d2ea20f","createUserFeedbacksUrl":"/engagements/nasa-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/nasa-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}