{"id":"36c2257e-864b-4187-bcd5-35f2fefcb37a","engagementId":"3f3df669-59f3-427e-8f62-e27ee03b1e2c","data":{"brief":{"id":"3d90afdf-db00-457f-af78-18ffe323ea97","name":"National Science Foundation - Vulnerability Disclosure Program ","tagline":"Where discoveries begin !","description":"\u003ch2\u003eIntroduction\u003c/h2\u003e\n\n\u003cp\u003eThe National Science Foundation (NSF) is an independent federal agency whose mission is \"to promote the progress of science; to advance the national health, prosperity, and welfare; to secure the national defense...\" NSF funds approximately 25 percent of all federally supported basic research conducted by America's colleges and universities.\u003c/p\u003e\n\n\u003cp\u003eProtecting information is integral to the NSF mission. NSF has a proactive structure to communicate about and implement NSF's Information Technology (IT) security and privacy program objectives and agency-wide initiatives. NSF aligns security and privacy program activities with industry standards and best practices. NSF is also committed to ensuring the security of the American public by protecting their information.\u003c/p\u003e\n\n\u003cp\u003eNSF welcomes the research and assessment of potential vulnerabilities from independent researchers. In compliance with the U.S. Department of Homeland Security Binding Operational Directive 20-01, Develop and Publish a Vulnerability Policy (September 2, 2020), the NSF Vulnerability Disclosure Policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities about NSF, and to convey NSF preferences in how to submit discovered vulnerabilities to NSF.\u003c/p\u003e\n\n\u003ch2\u003eNSF's Vulnerability Disclosure Policy describes:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhat systems and types of research are covered under the policy\u003c/li\u003e\n\u003cli\u003eHow to send vulnerability reports to NSF\u003c/li\u003e\n\u003cli\u003eHow long security researchers are asked to wait before publicly disclosing vulnerabilities\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eNSF encourages the public to use the processes described in this policy to report potential vulnerabilities in its systems.\u003c/p\u003e","industryTagId":"2a38890b-c88e-4bc0-8db0-02059f3fafe6","targetsOverview":"\u003cp\u003e\u003cstrong\u003eInformation submitted under this policy will be used for defensive purposes only - to mitigate or remediate vulnerabilities. If a researcher's findings include newly discovered vulnerabilities that affect all users of a product or service and not solely NSF, NSF may share the researcher's report with the Cybersecurity and Infrastructure Security Agency (CISA), where it will be handled under \u003ca href=\"https://www.cisa.gov/coordinated-vulnerability-disclosure-process\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCISA's coordinated vulnerability disclosure process\u003c/a\u003e. The researcher's name or contact information will not be shared without express permission.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003eVulnerability Research Authorization\u003c/h2\u003e\n\n\u003cp\u003eIf a researcher makes a good faith effort to comply with NSF's Vulnerability Disclosure Policy during his/her security research, NSF will consider the research to be authorized and NSF will work with the researcher to understand and resolve the issue quickly. NSF will not recommend or pursue legal action related to the research. Should legal action be initiated by a third party against the researcher for activities that were conducted in accordance with NSF's Vulnerability Disclosure Policy, NSF will make this authorization known.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003ePrinciples\u003c/h2\u003e\n\n\u003cp\u003eUnder this policy, a researcher is expected to comply with the following principles:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eEnsure test methods do not include unauthorized activities described below.\u003c/li\u003e\n\u003cli\u003eNotifies NSF as soon as possible after a real or potential security issue is discovered.\u003c/li\u003e\n\u003cli\u003eMakes every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.\u003c/li\u003e\n\u003cli\u003eOnly uses exploits to the extent necessary to confirm a vulnerability's presence. Does not use an exploit to compromise or exfiltrate data, establish command line access and/or persistence, or use the exploit to pivot to other systems.\u003c/li\u003e\n\u003cli\u003eAllows NSF 90 business days to resolve the issue before disclosing the vulnerability publicly.\u003c/li\u003e\n\u003cli\u003eDoes not submit a high volume of low-quality reports.\u003c/li\u003e\n\u003cli\u003eOnce a researcher has established that a vulnerability exists or encounters any sensitive data (including personally identifiable information, financial information, or proprietary information or trade secrets of any party), \u003cstrong\u003ethe researcher must stop their test, notify NSF immediately, and not disclose the data to anyone else\u003c/strong\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eTest Methods\u003c/h2\u003e\n\n\u003cp\u003eThe following test methods are not authorized:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNetwork denial of service (DoS or DDoS) tests or other tests that impair access to or damage a system or data\u003c/li\u003e\n\u003cli\u003ePhysical testing (e.g. office access, open doors, tailgating), social engineering (e.g. phishing, vishing), or any other non-technical vulnerability testing\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eScope\u003c/h2\u003e\n\n\u003cp\u003eNSF's Vulnerability Disclosure Policy applies to all NSF internet- accessible systems and services. \u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eVulnerabilities found in systems from NSF vendors fall outside the policy's scope and should be reported directly to the vendor according to the vendor's disclosure policy.\u003c/strong\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eReporting a Vulnerability\u003c/h2\u003e\n\n\u003cp\u003eResearchers who discover a potential vulnerability that may compromise NSF data or services are asked to follow the notification process below:\u003c/p\u003e\n\n\u003ch3\u003eNotification to NSF\u003c/h3\u003e\n\n\u003cp\u003eSubmit a report of a potential vulnerability to this program. Please provide the following information:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDescription of the vulnerability - provide a description of the potential vulnerability and the potential impact of exploitation.\u003c/li\u003e\n\u003cli\u003eLocation and potential impact - provide the URL or other identifier of the location of the vulnerability and the assessment conducted of the potential impact of the vulnerability.\u003c/li\u003e\n\u003cli\u003eTechnical information to reproduce the finding - provide technical information so that NSF IT specialists may investigate the finding, including the ability to reproduce the finding. Provide a detailed description of the steps needed to reproduce the vulnerability. Proof of concept scripts or screenshots are helpful.\u003c/li\u003e\n\u003cli\u003ePotential proof of concept code - provide a potential proof of concept code if possible.\u003c/li\u003e\n\u003cli\u003eThe researcher's acknowledgement of the following statement: \"By submitting a vulnerability, you acknowledge that you have no expectation of payment and that you expressly waive any future pay claims against the U.S. Government related to your submission.\"\u003c/li\u003e\n\u003cli\u003eResearcher submissions are acknowledged within three business days of submission.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eResearchers are asked to refrain from public announcement or discussion of their potential vulnerability findings for 90 business days from submission date to allow investigation and mitigation by NSF IT specialists.\u003c/p\u003e\n\n\u003ch3\u003eNSF Acknowledgement\u003c/h3\u003e\n\n\u003cp\u003eNSF will coordinate with the researcher as openly and as quickly as possible:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWithin three business days, NSF will acknowledge report receipt.\u003c/li\u003e\n\u003cli\u003eTo the best of NSF's ability, NSF will confirm the existence of the vulnerability to the researcher and be as transparent as possible about remediation, including on issues or challenges that may delay resolution.\u003c/li\u003e\n\u003cli\u003eNSF will maintain an open dialogue to discuss issues.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eNSF Investigation\u003c/h3\u003e\n\n\u003cp\u003eNSF IT specialists are responsible for beginning an investigation of publicly reported potential vulnerabilities within three business days of submission.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNSF IT specialists follow the NSF Vulnerability Management Procedure to mitigate potential vulnerabilities.\u003c/li\u003e\n\u003cli\u003eNSF IT specialists inform the researcher on mitigation or resolution if possible.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"a5e9f5ee-feb8-41ab-8a95-7dea47dc1efc","name":"In Scope ","targets":[{"id":"ecb5600a-2cfe-4284-be49-ea3b8c34c0f1","uri":"","name":"*.nsf.gov","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"683569b4-09d9-40e6-a0bd-b5afaa33b7cc","sortOrder":0},"sortOrder":0,"tags":[{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"ecb5600a-2cfe-4284-be49-ea3b8c34c0f1"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"ecb5600a-2cfe-4284-be49-ea3b8c34c0f1"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ecb5600a-2cfe-4284-be49-ea3b8c34c0f1"}],"recentChangeFlags":null},{"id":"75130464-e41c-4d8f-9681-7b7f8c4c90f1","uri":"","name":"*.research.gov","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e6977c03-70a1-4c0c-b086-395045d7c529","sortOrder":0},"sortOrder":0,"tags":[{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"75130464-e41c-4d8f-9681-7b7f8c4c90f1"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"75130464-e41c-4d8f-9681-7b7f8c4c90f1"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"75130464-e41c-4d8f-9681-7b7f8c4c90f1"}],"recentChangeFlags":null},{"id":"c83e6080-bf65-446b-89d5-dd2db583fa87","uri":"","name":"*.sac.gov","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"aa01c651-e088-4086-99ba-9fb86091d366","sortOrder":0},"sortOrder":0,"tags":[{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"c83e6080-bf65-446b-89d5-dd2db583fa87"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"c83e6080-bf65-446b-89d5-dd2db583fa87"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"c83e6080-bf65-446b-89d5-dd2db583fa87"}],"recentChangeFlags":null},{"id":"41d59fc9-0510-4c9b-8b80-e9138a4cdb50","uri":"","name":"*.usap.gov","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"37d192d9-1cb8-47a8-b471-afe3f2d1cb38","sortOrder":0},"sortOrder":0,"tags":[{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"41d59fc9-0510-4c9b-8b80-e9138a4cdb50"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"41d59fc9-0510-4c9b-8b80-e9138a4cdb50"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"41d59fc9-0510-4c9b-8b80-e9138a4cdb50"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null},{"id":"1afb2d6f-388e-40e0-aaa5-f7834d894f65","name":"Out of Scope","targets":[{"id":"41c0c544-1127-4ad8-8c0b-6af10df017b2","uri":"","name":"Anything not explicitly listed as 'In Scope'","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"17b2fb33-c80b-4dba-91a2-95b819b05152","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"3f3df669-59f3-427e-8f62-e27ee03b1e2c","code":"nsf-vdp","state":"in_progress","endsAt":null,"bountyId":"6d326ec0-87ae-4fca-87ab-a6904dacd2d3","startsAt":"2023-10-23T12:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Government","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/ae59/0424/0958cb18/94c9449c566113eb7f13193a0c410bee_1640798346574.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2023-10-23T12:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/nsf-vdp","changelogs":"/engagements/nsf-vdp/changelog","submissions":null,"announcements":"/engagements/nsf-vdp/announcements","hallOfFame":"/engagements/nsf-vdp/hall_of_fames","crowdstream":"/engagements/nsf-vdp/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/nsf-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=nsf-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/nsf-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/nsf-vdp/changelog","publishedAt":"2023-08-17T01:56:17.115Z","engagementChangelogUrl":"/engagements/nsf-vdp/changelog/36c2257e-864b-4187-bcd5-35f2fefcb37a","createUserFeedbacksUrl":"/engagements/nsf-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/nsf-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}