{"id":"fd927439-3332-4416-b6d3-b88f31184197","engagementId":"178fdf92-bd8c-4ac3-a862-853fe523f555","data":{"brief":{"id":"77239a26-53bd-44d9-a339-458b60e4c483","name":"New Relic Public Bug Bounty Program","tagline":"Data for engineers to monitor, debug, and improve their entire stack.","description":"\u003cp\u003eNew Relic is committed to the security of our customers and their data. We believe that engaging with security researchers through our bug bounty program is an important means of achieving our security goals.\u003c/p\u003e\n\n\u003cp\u003eIf you believe you have found a security vulnerability in one of our products or websites, we welcome and greatly appreciate you reporting it to New Relic. Please ensure that it is in scope for this program, paying close attention to the vulnerabilities and targets explicitly listed below as out of scope.\u003c/p\u003e\n\n\u003cp\u003eThe New Relic bug bounty program is primarily focussed on vulnerabilities in our platform and distributed products. We accept reports of website vulnerabilities, subject to the scope outlined below, but they are subject to lower bounty awards.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eIf you are a customer and have a password or account issue, please contact \u003ca href=\"https://support.newrelic.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic support\u003c/a\u003e.\u003c/strong\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003e\u003cstrong\u003eGetting started\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eTo get the most out of our program, you should familiarize yourself with New Relic and our products. You can \u003ca href=\"https://newrelic.com/signup\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esign up for a free trial\u003c/a\u003e, install our agents within your servers or applications, and read over \u003ca href=\"https://docs.newrelic.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eour extensive documentation\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eCredentials\u003c/strong\u003e\u003cbr\u003e\nAccounts on all publicly facing targets can be self-provisioned. \u003c/p\u003e\n\n\u003cp\u003ePlease sign up for an account using your \u003cstrong\u003e@bugcrowdninja.com\u003c/strong\u003e email address, any secondary accounts can be created using a modifier like: gr8hacks+nr2@buugcrowdninja.com. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eFree accounts are the only account type in scope for this program currently.\u003c/li\u003e\n\u003cli\u003eWhen registering an account, in the Name field, add “BugBounty-” to the beginning of your name, and use your BugCrowd username (e.g., BugBounty-gr8hacks). This will ensure that your account will not be marked as malicious by internal teams and you can test without issue.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, an explanation will be provided to the researcher. Rewards are awarded based on the merit of reported vulnerabilities, in New Relic’s sole discretion. Only the first verified report will be eligible for a reward. New Relic does not award Informational / P5 issues.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003ch3\u003eBug Bounty Program Policy\u003c/h3\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhat we expect of researchers:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eTo encourage coordinated disclosure, New Relic does not intend to initiate any legal action or law enforcement investigation against security researchers, unless it is required by law, if researchers adhere to the following guidelines:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eInclude all impacted account numbers on one.newrelic.com in your report\u003c/li\u003e\n\u003cli\u003eDo not access or modify customer data or other customer accounts; your research should be limited only to the account or data that belongs to you. To test, please \u003ca href=\"https://newrelic.com/signup\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esign up for a free trial\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eCarefully read the program details before researching your issue and only perform research that conforms to the rules and scope of this policy\u003c/li\u003e\n\u003cli\u003eComply with all applicable laws and regulations around security testing activities and respect New Relic’s intellectual property rights\u003c/li\u003e\n\u003cli\u003eReport full details of a discovered security issue to New Relic without making any information or details of the vulnerability public. Reports that refer to a pull request in our open source projects will not be rewarded.\u003c/li\u003e\n\u003cli\u003eAllow New Relic reasonable time to resolve the issue. Some reports may take time to properly investigate and remediate.\u003c/li\u003e\n\u003cli\u003eProvide as much detail as possible in your report in order to help New Relic’s security team and engineers reproduce the issue. If the report is not detailed enough to reproduce the issue, it will not be eligible for a reward.\u003c/li\u003e\n\u003cli\u003eMake all reasonable attempts in good faith to avoid destroying, stealing, modifying, damaging, violating or otherwise jeopardizing the confidentiality of any New Relic customer or New Relic data. This includes disrupting or degrading New Relic’s products and service to its customers.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eReporting issues\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003ePlease include detailed steps for replicating the finding; including screenshots, links you clicked on, pages visited, etc., we prefer detailed reproduction steps over video demos.\u003c/li\u003e\n\u003cli\u003eDescribe the versions of all relevant components of the attack (eg browser, OS, mobile app version).\u003c/li\u003e\n\u003cli\u003eDescribe a concrete attack scenario. How will the problem impact New Relic customers?\u003c/li\u003e\n\u003cli\u003ePlease group related issues into the same report rather than multiple nearly-identical reports. For example, an authorization bypass might affect a handful of endpoints. We ask that researchers who identify the same or similar types of issues in multiple locations throughout an application combine those findings into a single submission whose description includes the locations where the issues were identified.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhat you can expect from us:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e*Unless the circumstances warrant otherwise, New Relic will strive for open communication, which includes aiming to provide an initial response to the researcher within 30 days. Public disclosures should be mutually agreed upon between New Relic and the researcher. The nature and circumstances surrounding a vulnerability may consider more careful and private investigation and remediation.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNew Relic will pay qualifying bounty amounts below by category. We aim to be fair, and all reward amounts are at our discretion.\u003c/li\u003e\n\u003cli\u003eWhen duplicate reported vulnerabilities occur, we award the first report that we can completely and validly reproduce with the information provided.\u003c/li\u003e\n\u003cli\u003eMultiple reports related to the same root cause will be awarded one bounty; New Relic considers a vulnerability within a software module that runs on multiple subdomains to have the same root cause.\n\u003cem\u003eAll vulnerabilities are rated according to\u003c/em\u003e \u003cem\u003eNew Relic\u003c/em\u003e \u003cem\u003e's internal vulnerability remediation process at its sole discretion.\u003c/em\u003e This process takes into account the impact to New Relic and our customers if it was exploited.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eExample Issues by Severity\u003c/h3\u003e\n\n\u003cp\u003eBelow are some examples of vulnerabilities we're interested in seeing, and common severity ratings for\u003cbr\u003e\nthose issues. Note that the final severity rating may be higher or lower than what is listed here.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eCritical severity bugs:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eRemote code execution (RCE) on New Relic backend services\u003c/li\u003e\n\u003cli\u003eRCE on hosts via installed \u003ca href=\"https://docs.newrelic.com/docs/agents/manage-apm-agents/installation/compatibility-requirements-new-relic-agents\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic agents\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eRCE on host via \u003cstrong\u003eSynthetics\u003c/strong\u003e container escape\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eHigh severity bugs:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthentication bypass\u003c/li\u003e\n\u003cli\u003eAccess to sensitive data (e.g. Insights, Synthetics) from other New Relic accounts\u003c/li\u003e\n\u003cli\u003eSQL injection with demonstrated security impact\u003c/li\u003e\n\u003cli\u003eStored cross-site scripting (XSS) on that is likely to affect other users (except for frame-rpm.newrelic.com)\u003c/li\u003e\n\u003cli\u003eFlaws that could be used to exploit 3rd-party integration services\u003c/li\u003e\n\u003cli\u003eUnauthorized configuration changes to installed \u003ca href=\"https://docs.newrelic.com/docs/agents/manage-apm-agents/installation/compatibility-requirements-new-relic-agents\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic agents\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eTakeover of \u003ccode\u003enewrelic.com\u003c/code\u003e subdomains with arbitrary HTML and JavaScript\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eMedium severity bugs:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCross-site scripting (XSS) (except for frame-rpm.newrelic.com)\u003c/li\u003e\n\u003cli\u003eCross-site request forgery (CSRF/XSRF) of a non-idempotent (AKA state-changing) request\u003c/li\u003e\n\u003cli\u003eClickjacking on authenticated pages with sensitive state changes\u003c/li\u003e\n\u003cli\u003eDefault \u003ca href=\"https://docs.newrelic.com/docs/agents/manage-apm-agents/installation/compatibility-requirements-new-relic-agents\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic agents\u003c/a\u003e collecting and sending undocumented confidential data to New Relic\u003c/li\u003e\n\u003cli\u003eConfidential data disclosure with security impact\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of New Relic not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to New Relic, you can report it to \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/home\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Portal\u003c/a\u003e. However, be aware that such reports will be ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccepted Risks:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eCache purge requests are permitted without authentication. This has no significant impact on system throughput.\u003c/li\u003e\n\u003cli\u003eUser specified email contents (including invitations) are freeform text and may contain URLs and HTML tags. This is intensional and by design.\u003c/li\u003e\n\u003cli\u003eOur CORS policy is intentionally permissive to all subdomains of NewRelic.com and some other New Relic controlled domains.\u003c/li\u003e\n\u003cli\u003eAPIs can be called by Basic users including APIs where the UI is not presented to a Basic user. This is intentional. Basic users are shown a reduced UI but are welcome to use the platform via APIs.\u003c/li\u003e\n\u003cli\u003eIntrospection is allowed on the object model within NR1. The information is considered public.\u003c/li\u003e\n\u003cli\u003eThe default user (i.e. the user account used when no user has logged in) on the support forums can access various Salesforce objects. These objects contain only data that we consider to be public and access is read only.\u003c/li\u003e\n\u003cli\u003eA logged-on user can access forum contents and a limited subset of information about other users via direct or indirect object references in GET and POST requests, typically using the collaboration object. This information is intentionally public and has been carefully reviewed. This is expected and by design behavior.\u003c/li\u003e\n\u003cli\u003eIDP SSO intentionally places the determination of user validity into the control of an external SSO provider. It is the responsibility of the SSO provider to be an honest broker. Issues related to malicious use of IDP will not be accepted.\u003c/li\u003e\n\u003cli\u003eUnregistered domains or social media accounts linked from New Relic landing pages\u003c/li\u003e\n\u003cli\u003eLeakage of API keys from customer locations such as source code repositories or inactive/test accounts created by employees (i.e. API keys where there is no security impact from their disclosure) will be accepted, triaged, and resolved, but no bounty will be paid\u003c/li\u003e\n\u003cli\u003eInformation disclosures via /status or /metrics URLs without security impact\u003c/li\u003e\n\u003cli\u003eEXIF Geolocation Data Not Stripped From Uploaded Images\u003c/li\u003e\n\u003cli\u003eUsername / Account enumeration via email addresses\u003c/li\u003e\n\u003cli\u003eUsername and name disclosures on https://support.newrelic.com will be marked as Out of Scope, as this information is publicly available and does not constitute sensitive data. However, disclosures of email addresses or other PII remain in scope.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eExclusions:\u003c/h2\u003e\n\n\u003cp\u003eThe following are expressly prohibited (and void reward eligibility):\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePhysical attacks against New Relic employees, offices, and data centers. Social engineering of New Relic employees, contractors, vendors, or service providers (e.g. phishing, vishing, smishing, et al.).\u003c/li\u003e\n\u003cli\u003eAutomated security testing against New Relic applications or servers; scanning tools such as nmap or Burp Suite are acceptable for research, but we do not want reports generated by automated tools.\u003c/li\u003e\n\u003cli\u003eActions or testing that have the ability to take down the services, features, or functionality (e.g., DDoS) or impact the reliability of the services \u003c/li\u003e\n\u003cli\u003ePursuing vulnerabilities that send unsolicited bulk messages (spam).\u003c/li\u003e\n\u003cli\u003ePursuing vulnerabilities through the compromise of a New Relic customer or employee account (e.g. do not attempt to gain access to another user’s account or data).\u003c/li\u003e\n\u003cli\u003eKnowingly posting, transmitting, uploading, linking to, or sending any malware to New Relic or its employees.\u003c/li\u003e\n\u003cli\u003eMass account creation for testing against New Relic applications and services.\u003c/li\u003e\n\u003cli\u003e\"Brute force\" testing to determine whether rate limiting is in place for particular APIs or pieces of functionality or when mass creating pull requests against github.com repositories to determine CI/CD platform exploitability. Researchers should review individual repository files and builds to determine if they are a potential vulnerable target.\u003c/li\u003e\n\u003cli\u003eDisclosing information to the public without the express permission of New Relic or before the issue has been resolved\u003c/li\u003e\n\u003cli\u003eCreating new or multiple BugCrowd accounts to re-submit issues.\u003c/li\u003e\n\u003cli\u003eSubmitting reports for pull requests made by other users or submitting pull requests prior to submitting a BugCrowd report.\u003c/li\u003e\n\u003cli\u003eAI chatbot integrations on newrelic.com are explicitly out of scope\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut of Scope:\u003c/h2\u003e\n\n\u003cp\u003eOut of scope issues (not eligible for a reward). Note, this is not an exhaustive list and New Relic reserves the right to modify the severity of a finding based on internal context : \u003cbr\u003e\nInformation disclosure without significant security impact\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCSRF/XSRF without demonstrating security impact; CSRF on login/logout pages\u003c/li\u003e\n\u003cli\u003eSelf-XSS and any vulnerability exploitable only through Self-XSS\u003c/li\u003e\n\u003cli\u003eXSS issues concerning frame-rpm.newrelic.com\u003c/li\u003e\n\u003cli\u003eDenial-of-service (DoS) and Distributed denial-of-service (DDoS) vulnerabilities against NR1, Clients, or Agents; lack of rate limiting/load-testing issues on APIs\u003c/li\u003e\n\u003cli\u003eVulnerabilities affecting end of life, unmaintained, or unsupported services– such as browsers, platforms, or agents\u003c/li\u003e\n\u003cli\u003eVulnerabilities requiring unlikely user interaction or require physical access to a user's machine/device\u003c/li\u003e\n\u003cli\u003eVulnerabilities in Agents from insecure relative paths on a host system\u003c/li\u003e\n\u003cli\u003eVulnerabilities requiring a Man-in-the-Middle, with no other possible exploitation\u003c/li\u003e\n\u003cli\u003eAI chatbot integrations on newrelic.com are explicitly out of scope\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSynthetics\u003c/strong\u003e\n\n\u003cul\u003e\n\u003cli\u003eArbitrary Code Execution without demonstrating security impact\u003c/li\u003e\n\u003cli\u003eSandbox Escape without Container/Isolation Escape\u003c/li\u003e\n\u003cli\u003ePrivate Locations - Vulnerabilities from Out-of-Date/Vulnerable Packages\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAI\u003c/strong\u003e\n\n\u003cul\u003e\n\u003cli\u003ePrompt Injection that allows arbitrary prompts to be answered without demonstrated security impact\u003c/li\u003e\n\u003cli\u003eAny vulnerability that involves prompt disclosure\u003c/li\u003e\n\u003cli\u003eSelf-inflicted prompt injection vulnerabilities such as XSS without demonstrated security impact\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAccess Control\u003c/strong\u003e\n\n\u003cul\u003e\n\u003cli\u003eIssues concerning the \u003ca href=\"https://docs.newrelic.com/docs/accounts/original-accounts-billing/original-users-roles/users-roles-original-user-model\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eoriginal user model\u003c/a\u003e (including access control bypasses for Restricted users)\u003c/li\u003e\n\u003cli\u003eAccess control bypasses for Basic users in the \u003ca href=\"https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/new-relic-one-user-model-understand-user-structure\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic One user model\u003c/a\u003e for features limited to Full users; Basic users can become Full users at any time, therefore this isn't considered a security barrier\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eThird-party\u003c/strong\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities in 3rd-party scripts used on New Relic websites\u003c/li\u003e\n\u003cli\u003eVulnerabilities in Customer feedback submission forms (feedback.service.newrelic.com)\u003c/li\u003e\n\u003cli\u003eRemote code execution on a 3rd party CI/CD platform without the exposure of New Relic secrets or additional impact on New Relic data or infrastructure.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eThank you for helping keep \u003cstrong\u003eNew Relic\u003c/strong\u003e and our users secure!`\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"7c0e37a0-80ce-4ddd-b320-a9ba2dba62c8","name":"Tier One Targets","targets":[{"id":"4116e11e-f7ec-4d6b-aa87-764d3451bc75","uri":"https://one.newrelic.com","name":"https://one.newrelic.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7cb320ec-5a19-4e67-8565-c4870c1d7e28","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"4116e11e-f7ec-4d6b-aa87-764d3451bc75"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"4116e11e-f7ec-4d6b-aa87-764d3451bc75"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"4116e11e-f7ec-4d6b-aa87-764d3451bc75"},{"id":"c3412833-26e7-4bbd-907f-760d9da61232","name":"Newrelic","targetId":"4116e11e-f7ec-4d6b-aa87-764d3451bc75"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"4116e11e-f7ec-4d6b-aa87-764d3451bc75"}],"recentChangeFlags":null},{"id":"42cb5f74-2eff-4f4a-8761-3aaf9e63865e","uri":"https://play.google.com/store/apps/details?id=com.newrelic.rpm","name":"New Relic Android Application","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f7c8b00f-a0d5-4f99-a6dd-0741b4afb029","sortOrder":1},"sortOrder":1,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"42cb5f74-2eff-4f4a-8761-3aaf9e63865e"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"42cb5f74-2eff-4f4a-8761-3aaf9e63865e"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"42cb5f74-2eff-4f4a-8761-3aaf9e63865e"}],"recentChangeFlags":null},{"id":"6bd36718-049e-43d2-a20c-670e2b3d5ce8","uri":"https://apps.apple.com/ie/app/new-relic/id594038638","name":"New Relic iOS Application","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d8bd41ba-a417-40e6-ac87-32318c88045b","sortOrder":2},"sortOrder":2,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"6bd36718-049e-43d2-a20c-670e2b3d5ce8"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"6bd36718-049e-43d2-a20c-670e2b3d5ce8"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"6bd36718-049e-43d2-a20c-670e2b3d5ce8"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"9ea7e665-1233-4bc8-86e4-57cf26fe3ee2","p1MaxCents":600000,"p1MinCents":600000,"p2MaxCents":250000,"p2MinCents":250000,"p3MaxCents":50000,"p3MinCents":50000,"p4MaxCents":25000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eNew Relic One\u003c/strong\u003e:\u003cbr\u003e\nNew Relic One is the industry’s first entity-centric observability platform. This platform allows our customers to view across accounts and products. Assets in both the North American and European region are in scope for our bug bounty program, except where otherwise noted. \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNew Relic allows sign-in via direct login, SSO, and social logins.\n\n\u003cul\u003e\n\u003cli\u003eWhen logging in via social login, it is expected that the session will persist as long as the third party service still has a valid session.\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003eAll services can be found at: \u003ca href=\"https://one.newrelic.com/all-capabilities\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://one.newrelic.com/all-capabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eNew Relic software distributed via GitHub can be found at: \u003ca href=\"https://github.com/newrelic\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/newrelic\u003c/a\u003e\n\n\u003cul\u003e\n\u003cli\u003eNew Relic agents, both infrastructure and language, are used to send information (running processes, memory usage, etc.) from the system where they are installed to be viewed within the New Relic web application.\u003c/li\u003e\n\u003cli\u003eWe may provide rewards for security issues found within our agents that could reduce the security of the application the agent is integrated with. Rewards are based on the default configuration settings, but agents that show problems due to a configuration change may be eligible for a reward.\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003eSynthetics minions are sandboxed virtual machines that run monitors (scripts) to gather information about your websites, critical business transactions, and API endpoints. Minions can run in our data center or privately within your own infrastructure. We recommend familiarizing yourself with the product by reading our documentation.\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNote that out-of-date packages running on these minions are not in scope for this program. Minions are intended to be updated from within the VM or with future releases.\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003eThe \u003ca href=\"https://docs.newrelic.com/docs/agents/manage-apm-agents/installation/compatibility-requirements-new-relic-agents\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic agents\u003c/a\u003e are designed to collect data and send it back for display within the \u003ca href=\"https://docs.newrelic.com/docs/licenses/new-relic-products\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic products\u003c/a\u003e. Traffic between the agents and New Relic backend services may be inspected and reports concerning issues with how the agent connects and transports information are acceptable.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eNew Relic Mobile Applications:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe \u003ca href=\"https://play.google.com/store/apps/details?id=com.newrelic.rpm\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic Android app\u003c/a\u003e and \u003ca href=\"https://apps.apple.com/ie/app/new-relic/id594038638\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic iOS App\u003c/a\u003e lets you access your data wherever you are. Receive alerts, view, query, and share dashboards, and more all from your mobile device.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003e⚠️ Notice [Effective August 17, 2026 at 07:12 UTC] : All Agents listed below are Temporarily Out of Scope. Reports submitted after this notice was posted will not be eligible for rewards. We will update this section when they return to scope.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch3\u003eTier One Agents (with documentation references):\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eInfrastructure agents - The \u003ca href=\"https://docs.newrelic.com/docs/infrastructure/infrastructure-monitoring/get-started/get-started-infrastructure-monitoring/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic Infrastructure agents\u003c/a\u003e are used to send information (running processes, memory usage, etc.) from Windows and Linux servers to be viewed within the New Relic One platform.\u003c/li\u003e\n\u003cli\u003eBrowser agent - The \u003ca href=\"https://docs.newrelic.com/docs/browser/new-relic-browser/getting-started/introduction-new-relic-browser\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic Browser agent\u003c/a\u003e is \u003ca href=\"https://docs.newrelic.com/docs/browser/new-relic-browser/installation/install-new-relic-browser-agent\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003edeployed as a JavaScript snippet\u003c/a\u003e by way of a \u003ca href=\"https://docs.newrelic.com/docs/browser/new-relic-browser/getting-started/compatibility-requirements-new-relic-browser\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esupported APM agent or web application\u003c/a\u003e. It is designed to collect data about the running application and send it back for display within the New Relic One platform\u003c/li\u003e\n\u003cli\u003eAndroid agent - The \u003ca href=\"https://docs.newrelic.com/docs/mobile-monitoring/new-relic-mobile-android/get-started/introduction-new-relic-mobile-android\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic Android agent\u003c/a\u003e is \u003ca href=\"https://docs.newrelic.com/docs/mobile-monitoring/new-relic-mobile-android/install-configure/install-android-apps-gradle-android-studio\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003einstalled via Gradle\u003c/a\u003e within a \u003ca href=\"https://docs.newrelic.com/docs/mobile-monitoring/new-relic-mobile-android/get-started/new-relic-android-compatibility-requirements\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esupported Android application\u003c/a\u003e. It is designed to collect data about the running application and send it back for display within \u003ca href=\"https://docs.newrelic.com/docs/mobile-monitoring/new-relic-mobile/getting-started/introduction-new-relic-mobile\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic Mobile\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eiOS agent - The \u003ca href=\"https://docs.newrelic.com/docs/mobile-monitoring/new-relic-mobile-ios/get-started/introduction-new-relic-mobile-ios\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic iOS agent\u003c/a\u003e is \u003ca href=\"https://docs.newrelic.com/docs/mobile-monitoring/new-relic-mobile-ios/installation/ios-manual-installation\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003einstalled as a framework\u003c/a\u003e or \u003ca href=\"https://docs.newrelic.com/docs/mobile-monitoring-installation/cocoapods-installation-and-configuration\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003evia CocoaPods\u003c/a\u003e within a \u003ca href=\"https://docs.newrelic.com/docs/mobile-monitoring/new-relic-mobile-ios/get-started/new-relic-ios-compatibility-requirements\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esupported iOS application\u003c/a\u003e. It is designed to collect data about the running application and send it back for display within \u003ca href=\"https://docs.newrelic.com/docs/mobile-monitoring/new-relic-mobile/getting-started/introduction-new-relic-mobile\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic Mobile\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eGo agent - The \u003ca href=\"https://docs.newrelic.com/docs/agents/go-agent/get-started/introduction-new-relic-go\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic Go agent\u003c/a\u003e is \u003ca href=\"https://docs.newrelic.com/docs/agents/go-agent/installation/install-new-relic-go\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003einstalled\u003c/a\u003e within a \u003ca href=\"https://docs.newrelic.com/docs/agents/go-agent/get-started/go-agent-compatibility-requirements\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esupported Go application\u003c/a\u003e. It is designed to collect data about the running application and send it back for display within \u003ca href=\"https://docs.newrelic.com/docs/apm/new-relic-apm/getting-started/introduction-new-relic-apm\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic APM\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eNode.js agent - The \u003ca href=\"https://docs.newrelic.com/docs/agents/nodejs-agent/getting-started/introduction-new-relic-nodejs\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic Node.js agent\u003c/a\u003e can by \u003ca href=\"https://docs.newrelic.com/docs/agents/nodejs-agent/installation-configuration/install-maintain-nodejs\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003einstalled via npm\u003c/a\u003e within a \u003ca href=\"https://docs.newrelic.com/docs/agents/nodejs-agent/getting-started/new-relic-nodejs#requirements\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esupported Node.js application\u003c/a\u003e. It is designed to collect data about the running application and send it back for display within the New Relic One platform.\u003c/li\u003e\n\u003cli\u003eRuby agent - The \u003ca href=\"https://docs.newrelic.com/docs/agents/ruby-agent/getting-started/introduction-new-relic-ruby\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic Ruby agent\u003c/a\u003e is \u003ca href=\"https://docs.newrelic.com/docs/agents/ruby-agent/installation-configuration/ruby-agent-installation\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003einstalled as a Ruby gem\u003c/a\u003e within a \u003ca href=\"https://docs.newrelic.com/docs/agents/ruby-agent/getting-started/ruby-agent-requirements-supported-frameworks\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esupported Ruby application\u003c/a\u003e. It is designed to collect data about the running application and send it back for display within the New Relic One platform.\u003c/li\u003e\n\u003cli\u003eUnity agent - The \u003ca href=\"https://docs.newrelic.com/docs/mobile-monitoring/new-relic-mobile-unity/get-started/introduction-new-relic-unity\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic Unity agent\u003c/a\u003e is \u003ca href=\"https://docs.newrelic.com/docs/mobile-monitoring/new-relic-mobile-unity/install-configure/unity-plugin-installation-configuration\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003einstalled within a Unity application\u003c/a\u003e on iOS or Android. It is designed to collect data about the running application and send it back for display within the New Relic One platform.\u003c/li\u003e\n\u003cli\u003ePHP agent - The \u003ca href=\"https://docs.newrelic.com/docs/agents/php-agent/getting-started/introduction-new-relic-php\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNew Relic PHP agent\u003c/a\u003e can be \u003ca href=\"https://docs.newrelic.com/docs/agents/php-agent/installation/php-agent-installation-overview\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003einstalled\u003c/a\u003e within a \u003ca href=\"https://docs.newrelic.com/docs/agents/php-agent/getting-started/php-agent-compatibility-requirements\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esupported PHP application\u003c/a\u003e. It is designed to collect data about the running application and send it back for display within the New Relic One platform.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":6000,"max":6000},"2":{"min":2500,"max":2500},"3":{"min":500,"max":500},"4":{"min":250,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"0e3d4446-fcf1-44f6-9e31-bb6b8b209fd9","name":"Tier Two Targets","targets":[{"id":"4c06f9f8-8928-4f64-83ea-5978773daafd","uri":"","name":"*.nr-data.net","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5bf473a2-8eac-4d12-a871-9275ca3f5f75","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"4c06f9f8-8928-4f64-83ea-5978773daafd"},{"id":"1f10e73e-4eef-42c1-ba6b-6df69f8dc8fa","name":"Rust","targetId":"4c06f9f8-8928-4f64-83ea-5978773daafd"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"4c06f9f8-8928-4f64-83ea-5978773daafd"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"4c06f9f8-8928-4f64-83ea-5978773daafd"},{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"4c06f9f8-8928-4f64-83ea-5978773daafd"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"4c06f9f8-8928-4f64-83ea-5978773daafd"}],"recentChangeFlags":null},{"id":"9a3329c8-2a77-4720-af4c-1ff1c6f0134c","uri":"","name":"*.nr-ops.net","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"37961d6f-a901-422e-9455-05563ea9c8bc","sortOrder":1},"sortOrder":1,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"9a3329c8-2a77-4720-af4c-1ff1c6f0134c"},{"id":"1f10e73e-4eef-42c1-ba6b-6df69f8dc8fa","name":"Rust","targetId":"9a3329c8-2a77-4720-af4c-1ff1c6f0134c"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"9a3329c8-2a77-4720-af4c-1ff1c6f0134c"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"9a3329c8-2a77-4720-af4c-1ff1c6f0134c"},{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"9a3329c8-2a77-4720-af4c-1ff1c6f0134c"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"9a3329c8-2a77-4720-af4c-1ff1c6f0134c"}],"recentChangeFlags":null},{"id":"3140cdbb-964e-4e6a-b86d-3ba8467b4627","uri":"https://docs.newrelic.com/","name":"https://docs.newrelic.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b8178115-ad37-44d6-8e8d-0a123fe6b665","sortOrder":2},"sortOrder":2,"tags":[{"id":"21bf0b21-e645-4730-b030-be773c64efc7","name":"Gatsby","targetId":"3140cdbb-964e-4e6a-b86d-3ba8467b4627"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"3140cdbb-964e-4e6a-b86d-3ba8467b4627"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"3140cdbb-964e-4e6a-b86d-3ba8467b4627"},{"id":"c3412833-26e7-4bbd-907f-760d9da61232","name":"Newrelic","targetId":"3140cdbb-964e-4e6a-b86d-3ba8467b4627"}],"recentChangeFlags":null},{"id":"406fee97-2498-4936-87a4-d88b66500736","uri":"https://newrelic.com/","name":"https://newrelic.com/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b495b42f-027d-4527-9e67-fa0716ef546a","sortOrder":3},"sortOrder":3,"tags":[{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"406fee97-2498-4936-87a4-d88b66500736"},{"id":"4077ab03-37ce-4c7d-8634-ea59ba5ef456","name":"Varnish","targetId":"406fee97-2498-4936-87a4-d88b66500736"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"406fee97-2498-4936-87a4-d88b66500736"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"406fee97-2498-4936-87a4-d88b66500736"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"406fee97-2498-4936-87a4-d88b66500736"}],"recentChangeFlags":null},{"id":"b9319a5a-ab35-4100-8fc2-335c2fa59f1f","uri":"https://newrelic.com/blog","name":"https://newrelic.com/blog","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2025ab05-99d3-4ad4-a3da-73801a68d983","sortOrder":4},"sortOrder":4,"tags":[{"id":"4077ab03-37ce-4c7d-8634-ea59ba5ef456","name":"Varnish","targetId":"b9319a5a-ab35-4100-8fc2-335c2fa59f1f"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"b9319a5a-ab35-4100-8fc2-335c2fa59f1f"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"b9319a5a-ab35-4100-8fc2-335c2fa59f1f"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b9319a5a-ab35-4100-8fc2-335c2fa59f1f"}],"recentChangeFlags":null},{"id":"d5188c10-faba-4d24-9dd4-df1717d64efc","uri":"https://support.newrelic.com/","name":"https://support.newrelic.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"66bc42e1-db5b-46a4-a4f3-5401280e8c9d","sortOrder":5},"sortOrder":5,"tags":[{"id":"481480d5-cf87-4122-900f-18307fe19a86","name":"Salesforce","targetId":"d5188c10-faba-4d24-9dd4-df1717d64efc"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d5188c10-faba-4d24-9dd4-df1717d64efc"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"d5188c10-faba-4d24-9dd4-df1717d64efc"}],"recentChangeFlags":null},{"id":"8b839f7c-63a0-4e98-8ee8-2621bd67b0f8","uri":"https://forum.newrelic.com","name":"https://forum.newrelic.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ba3a3d06-5983-4f70-9858-929e471026c6","sortOrder":6},"sortOrder":6,"tags":[{"id":"481480d5-cf87-4122-900f-18307fe19a86","name":"Salesforce","targetId":"8b839f7c-63a0-4e98-8ee8-2621bd67b0f8"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"8b839f7c-63a0-4e98-8ee8-2621bd67b0f8"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"8b839f7c-63a0-4e98-8ee8-2621bd67b0f8"}],"recentChangeFlags":null},{"id":"078c7fe1-afb0-4bb7-a2cb-77c43ae56e8c","uri":"https://knowledge.newrelic.com/","name":"https://knowledge.newrelic.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2291c7a9-9030-45f1-89da-de84ef7db353","sortOrder":7},"sortOrder":7,"tags":[{"id":"481480d5-cf87-4122-900f-18307fe19a86","name":"Salesforce","targetId":"078c7fe1-afb0-4bb7-a2cb-77c43ae56e8c"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"078c7fe1-afb0-4bb7-a2cb-77c43ae56e8c"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"078c7fe1-afb0-4bb7-a2cb-77c43ae56e8c"}],"recentChangeFlags":null},{"id":"a08006da-1a2a-494c-8967-0685e1f84d50","uri":"https://learn.newrelic.com/","name":"https://learn.newrelic.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9a656e1a-f6df-4220-aac2-2d9c3ebcaf86","sortOrder":8},"sortOrder":8,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a08006da-1a2a-494c-8967-0685e1f84d50"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"a08006da-1a2a-494c-8967-0685e1f84d50"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"a08006da-1a2a-494c-8967-0685e1f84d50"}],"recentChangeFlags":null},{"id":"f40d6ff7-8764-406b-bebb-bf6bd9feb87a","uri":"https://developer.newrelic.com/","name":"https://developer.newrelic.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b13ab0c9-4edf-4d79-8d3f-bf61ddc842aa","sortOrder":9},"sortOrder":9,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"f40d6ff7-8764-406b-bebb-bf6bd9feb87a"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"f40d6ff7-8764-406b-bebb-bf6bd9feb87a"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f40d6ff7-8764-406b-bebb-bf6bd9feb87a"},{"id":"c3412833-26e7-4bbd-907f-760d9da61232","name":"Newrelic","targetId":"f40d6ff7-8764-406b-bebb-bf6bd9feb87a"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"70416b92-5d96-4079-be7c-b67db66d96ce","p1MaxCents":75000,"p1MinCents":75000,"p2MaxCents":50000,"p2MinCents":50000,"p3MaxCents":20000,"p3MinCents":20000,"p4MaxCents":10000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eNew Relic website:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAll assets under \u003cem\u003e*.newrelic.com\u003c/em\u003e are in scope for our bug bounty program, except where otherwise noted. \n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eServices hosted by third party providers are out of scope and should not be tested against.\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eNew Relic blog:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOur blog is hosted externally by Pantheon. Issues within this application or regarding our content should be reported here. No security testing should be done against the platform itself. Any security issues found within the platform should be reported directly to Pantheon. \n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eUnregistered domains or social media accounts linked from this domain are not in scope for bounty.\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eNew Relic Support websites:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIncludes support.newrelic.com, forum.newrelic.com, knowledge. newrelic.com\n\n\u003cul\u003e\n\u003cli\u003eThese sites are built on the Salesforce Experience Cloud platform. Issues unique to our installation are in scope for bounties. \n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eIssues with Salesforce itself are not in scope and should not be researched on our instance.\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003eSpam, brute forcing, and social engineering are strictly forbidden. All care should be made to avoid generating new posts or otherwise affecting the experience of other users on the forum. \n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNote: No XSS payloads should be attempted unless there is reason to believe our instance is uniquely vulnerable due to our modifications. If an issue is discovered, the payload should immediately be deleted and reported to prevent other users from encountering it.\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eNew Relic University:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOur training portal is hosted externally by Skilljar. Issues within this application or regarding our content should be reported here. \n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNo security testing should be done against the platform itself. Any security issues found within the platform should be reported to the Skilljar security team.\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":750,"max":750},"2":{"min":500,"max":500},"3":{"min":200,"max":200},"4":{"min":100,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"496e11c7-0736-454f-a8c8-2403558fab62","name":"Out of Scope","targets":[{"id":"b08f0be2-0486-4136-abb5-c7ffe56468ab","uri":"","name":"https://status.newrelic.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"78fcb741-b154-44aa-86e6-818a97bb01d1","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"3319318d-3f0d-4a01-84ab-64f22dd5b25f","uri":"","name":"New Relic open source software repos in github.com not in the list of agents or on docs.newrelic.com; New Relic Example Code, New Relic Experimental and Archived repos are explicitly out of scope.","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"35806fe2-3d12-48af-a2c2-1105a424ac76","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"213c047e-919d-49f3-9519-00ad60d73411","uri":"","name":"https://iopipe.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d57e4cd2-5e35-4ef2-925e-4cd6d0010e20","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"b7c5daab-d0f6-4354-b21a-5893072a4ca4","uri":"","name":"https://one.newrelic.com/help-xp - This specific endpoint is excluded from scope ","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a7128551-daa6-4717-909e-e6d3dde58c1c","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"33f3e475-73da-452e-8f4f-6687df94047a","uri":"","name":"https://newrelic.com/lp/1mind-ai-chat","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"35e40a0b-3449-4c46-aeec-554d6b656b9e","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":2,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"178fdf92-bd8c-4ac3-a862-853fe523f555","code":"newrelic-mbb-og-public","state":"in_progress","endsAt":null,"bountyId":"d9b97438-90c8-4771-8bcc-ea97628328c2","startsAt":"2024-08-21T13:00:56Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/0126/41bb/a11b7b93/9a6cd3dd42370f50ea1490e93239ca8a_new_relic_inc__logo.jpeg","logoBackgroundColor":"#FFFFFF","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-09-03T21:44:17.739Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/newrelic-mbb-og-public","changelogs":"/engagements/newrelic-mbb-og-public/changelog","submissions":null,"announcements":"/engagements/newrelic-mbb-og-public/announcements","hallOfFame":"/engagements/newrelic-mbb-og-public/hall_of_fames","crowdstream":"/engagements/newrelic-mbb-og-public/crowdstream"},"announcementsCount":6,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/newrelic-mbb-og-public/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=newrelic-mbb-og-public\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/newrelic-mbb-og-public/engagement_subscribers","engagementChangelogsUrl":"/engagements/newrelic-mbb-og-public/changelog","publishedAt":"2026-09-09T10:51:22.515Z","engagementChangelogUrl":"/engagements/newrelic-mbb-og-public/changelog/fd927439-3332-4416-b6d3-b88f31184197","createUserFeedbacksUrl":"/engagements/newrelic-mbb-og-public/feedbacks","engagementCrowdstreamUrl":"/engagements/newrelic-mbb-og-public/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}