{"id":"f01c2a8a-a4b8-4c03-af44-c8ddff662dc0","engagementId":"217e28f7-e325-473b-80f1-394a356c9f1a","data":{"brief":{"id":"a3521df1-180f-4f03-8346-8f8da33719d9","name":"New Balance VDP","tagline":"New Balance is an international corporation, selling footwear and apparel in over 120 countries and employing over 8,000 associates worldwide.","description":"\u003ch2\u003eIntroduction\u003c/h2\u003e\n\n\u003cp\u003eNew Balance Athletics, Inc. and our global affiliates (“New Balance”) is committed to the security of our online platform and services. We appreciate the hard work the security research community puts into helping companies like New Balance identify risks in our platform and services. If you're a security researcher and have discovered security-related risks in our platform or services, we encourage you to submit your findings responsibly.\u003c/p\u003e\n\n\u003cp\u003eWe will validate and fix security risks as soon as possible. We will not take legal action against and/or suspend/terminate accounts of security researchers who discover and report risks responsibly in accordance with the terms of this program. New Balance may modify the terms of this Responsible Disclosure Program at any time by posting an updated version here.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eNoncompliance\u003c/h2\u003e\n\n\u003cp\u003ePublic disclosure of the submission details of any identified or alleged vulnerability without express written consent from New Balance will result in immediate dismissal from this Responsible Disclosure Program. Such disclosure may also violate applicable law(s) and New Balance reserves all rights to seek legal action.\u003c/p\u003e\n\n\u003cp\u003eIn addition, to remain compliant under this Responsible Disclosure Program, you are \u003cstrong\u003eprohibited\u003c/strong\u003e from:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAccessing, downloading, and/or modifying data residing in an account that does not belong to you.\u003c/li\u003e\n\u003cli\u003eExecuting or attempting to execute any “Denial of Service” attack.\u003c/li\u003e\n\u003cli\u003ePosting, transmitting, uploading, linking to, sending, and/or storing any malicious software.\u003c/li\u003e\n\u003cli\u003eTesting in a manner that would result in the sending of unsolicited or unauthorized junk mail, spam, pyramid schemes, and/or other forms of unsolicited messages.\u003c/li\u003e\n\u003cli\u003eTesting in a manner that would degrade the operation of any New Balance system.\u003c/li\u003e\n\u003cli\u003eTesting third-party applications, websites, and/or services that integrate with or link to New Balance systems.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"9ed1ce49-a148-438f-92d3-0b8d70b6a8ae","targetsOverview":"\u003ch2\u003eProgram Rules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eRemember to only access your own accounts - create multiple accounts if you want to test for IDOR, BAC or other vulnerabilities\u003c/li\u003e\n\u003cli\u003eWe encourage you to keep our data safe and secure, so avoid any attempts to modify or delete information. \u003c/li\u003e\n\u003cli\u003eRefraining from attempting denial-of-service attacks and uploading malware.\u003c/li\u003e\n\u003cli\u003eKeep content appropriate and respectful, as this is a shared space. \u003c/li\u003e\n\u003cli\u003eAvoid using brute-force methods for logins. \u003c/li\u003e\n\u003cli\u003eStop testing if you believe your actions are having a negative impact on the site and let us know\u003c/li\u003e\n\u003cli\u003eIf you can do any of the following, please notify us immediately:\n\n\u003cul\u003e\n\u003cli\u003eAccess other account data\u003c/li\u003e\n\u003cli\u003eUploading a shell (that is usable)\u003c/li\u003e\n\u003cli\u003eAchieving RCE (remote code execution)\u003c/li\u003e\n\u003cli\u003eAchieving command injection\u003c/li\u003e\n\u003cli\u003eAbility to read any operating system file outside the web directories \u003c/li\u003e\n\u003cli\u003eAny other vulnerability you consider critical\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eHypothetical vulnerabilities will not be accepted. Any vulnerability must be reported in a way that makes it possible to replicate it. Provide a working PoC. \u003c/li\u003e\n\u003cli\u003eAny vulnerability reported under this policy must be kept confidential.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eMissing or weak security headers (generic) without exploitability (e.g., generic CSP, X‑Frame‑Options, HSTS recommendations absent a working exploit).\u003c/li\u003e\n\u003cli\u003eCookies missing HttpOnly/Secure for non‑sensitive cookies only.\u003c/li\u003e\n\u003cli\u003eContent spoofing or text injection without the ability to modify HTML/CSS or cause a security impact (e.g., self‑XSS, self‑HTML injection, non‑persistent UI text changes).\u003c/li\u003e\n\u003cli\u003eCache‑control issues on non‑sensitive pages.\u003c/li\u003e\n\u003cli\u003ePresence of browser autocomplete on form fields (without security impact).\u003c/li\u003e\n\u003cli\u003eOPTIONS / TRACE HTTP methods enabled without an exploit path.\u003c/li\u003e\n\u003cli\u003eSocial‑engineering‑dependent attacks against employees or vendors.\u003c/li\u003e\n\u003cli\u003eSSL/TLS “best practice” gaps without a working exploit (e.g., ciphers/hardening recommendations).\u003c/li\u003e\n\u003cli\u003eAttacks requiring Man‑in‑the‑Middle (MitM), device compromise, or physical access to a user’s device.\u003c/li\u003e\n\u003cli\u003eAny activity that could disrupt service (e.g., DoS, DDoS, resource‑exhaustion tests).\u003c/li\u003e\n\u003cli\u003eUse of outdated or known‑vulnerable software/libraries without a working PoC or demonstrated impact.\u003c/li\u003e\n\u003cli\u003eEmail authentication configuration (DMARC, DKIM, SPF) issues without demonstrated abuse leading to security impact.\u003c/li\u003e\n\u003cli\u003eCache poisoning without impact; CPDoS (Cache‑Poisoned DoS) is out of scope.\u003c/li\u003e\n\u003cli\u003eLack of email address verification during account registration\u003c/li\u003e\n\u003cli\u003eMixed content issues\u003c/li\u003e\n\u003cli\u003eRate limiting\u003c/li\u003e\n\u003cli\u003eAll sessions not being invalidated on logout from a session\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ecreate a ticket with Bugcrowd Support\u003c/a\u003e for clarification before proceeding.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"6da4c91a-cdd5-47b6-aac1-84e69639a37c","name":"In Scope","targets":[{"id":"574f837e-bb1f-4a59-b4d8-742bfe1dff54","uri":"","name":"https://*.newbalance.*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"df424c74-6e5f-41f2-acb3-fcbdc5186b49","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null},{"id":"4759ea20-9705-4003-a601-16eddbd75dc9","name":"Out of Scope","targets":[{"id":"7ce0c3dc-2319-4b11-b3b3-97b409ba5bfb","uri":"","name":"Excludes Family Brands: Warrior and Brine","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6138c4b5-108d-4637-9f2e-114e346202e0","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"217e28f7-e325-473b-80f1-394a356c9f1a","code":"newbalance-vdppro","state":"in_progress","endsAt":null,"bountyId":"d3f1adc7-f565-4ce4-828d-9a89a738aba1","startsAt":"2025-06-24T19:43:30Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Retail","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/3e51/46a6/08fbd073/133754cd66a3060a4ce7e132ff56b90a_NB.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-06-24T19:43:30.803Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/newbalance-vdppro","changelogs":"/engagements/newbalance-vdppro/changelog","submissions":null,"announcements":"/engagements/newbalance-vdppro/announcements","hallOfFame":"/engagements/newbalance-vdppro/hall_of_fames","crowdstream":"/engagements/newbalance-vdppro/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/newbalance-vdppro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=newbalance-vdppro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/newbalance-vdppro/engagement_subscribers","engagementChangelogsUrl":"/engagements/newbalance-vdppro/changelog","publishedAt":"2026-07-16T13:26:22.714Z","engagementChangelogUrl":"/engagements/newbalance-vdppro/changelog/f01c2a8a-a4b8-4c03-af44-c8ddff662dc0","createUserFeedbacksUrl":"/engagements/newbalance-vdppro/feedbacks","engagementCrowdstreamUrl":"/engagements/newbalance-vdppro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}