{"id":"e680db64-f4c3-4e11-bb1f-db7b32c2b905","engagementId":"08a9c0ef-12b0-490c-acdb-785a11f85e72","data":{"brief":{"id":"41c08e69-1a37-4c54-b277-b9fcb8b8264d","name":"Octopus Deploy","tagline":"Submit your finding to the program!","description":"\u003cp\u003eOctopus Deploy invites you to test and help secure our standalone on premise products: Octopus Server \u0026amp; Octopus Tentacle. \u003c/p\u003e\n\n\u003cp\u003eWe appreciate your efforts and hard work in making Octopus Deploy a more secure product, and look forward to working with the researcher community to create a meaningful and successful bug bounty program. \u003c/p\u003e\n\n\u003cp\u003eGood luck and happy hunting! \u003c/p\u003e\n\n\u003ch2\u003eRatings / Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority. Please see below for any deviations from the standard VRT.\u003c/em\u003e \u003c/p\u003e\n\n\u003cp\u003eNote: This application shares some of the same codebase as the cloud version. It is still highly recommended that you submit your vulnerability, but please note that issues found in this shared codebase would be considered duplicates of each other.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorised on the targets listed as in scope. Any domain/property of Octopus not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you identify a security vulnerability on a target not in scope but demonstrably belongs to Octopus, you can report it to this program. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTarget Information\u003c/h2\u003e\n\n\u003cp\u003eThis program only provides monetary rewards for vulnerability research on supported versions of:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOctopus Server\u003c/li\u003e\n\u003cli\u003eOctopus Tentacle\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eCurrently, supported versions on our website are available to \u003ca href=\"https://octopus.com/downloads\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003edownload\u003c/a\u003e. They fall out of support 6 months after becoming available.\u003c/p\u003e\n\n\u003cp\u003eA \u003ca href=\"https://octopus.com/docs/getting-started\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003egetting started guide\u003c/a\u003e has been provided to assist you with installing Octopus Deploy.\u003c/p\u003e\n\n\u003ch3\u003eFree license\u003c/h3\u003e\n\n\u003cp\u003ePlease sign up for an account on octopus.com using your @bugcrowdninja.com email address \u003ca href=\"https://octopus.com/start/server\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://researcherdocs.bugcrowd.com/v2.0/docs/your-bugcrowdninja-email-address\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003ePlease be aware that octopus.com is not in scope and is not an authorised target of this program. If you are interested in researching octopus.com, please check out our dedicated bounty program for it \u003ca href=\"https://bugcrowd.com/octopus-og\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cp\u003eFeel free to explore our product security and give us feedback, but please keep some things in mind:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOctopus Server and Tentacle are designed to run privileged, arbitrary code on the environments that they are installed on. We expect code to run under the controlled conditions for which the product is intended. We will only reward research in arbitrary code execution if it results in privileged execution on the server via a novel or unintended execution vector (e.g. command injection through some mechanism that isn’t intended to run script code).\u003c/li\u003e\n\u003cli\u003eWe consider bugs that allow users to elevate their privilege within our system to be a priority. Our RBAC is comprehensive, and we want to ensure it is safe for our customers.\u003c/li\u003e\n\u003cli\u003eMessaging between the server and the tentacle is intended to be encrypted, so broken encryption vulnerabilities that lead to a demonstrated, reproducible leak of secret information over the wire are also a priority for us to fix if they occur.\u003c/li\u003e\n\u003cli\u003eWe do our best to ensure that secrets are removed from task logs; however, it isn’t always possible, given the nature of arbitrary code execution. We are concerned about scenarios when variables explicitly marked as ‘sensitive’ are not correctly masked in the task logs for a deployment.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope and Other Exclusions\u003c/h2\u003e\n\n\u003cp\u003eTo be as clear as possible, the following are \u003cem\u003ealso out of scope for testing\u003c/em\u003e:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny of our closed-source tooling, build chain, public-facing repositories, email and IM servers, social media accounts or 3rd party SaaS products that we use to deliver our services.\u003c/li\u003e\n\u003cli\u003eAny internal or development services.\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g. stack traces, application or server errors).\u003c/li\u003e\n\u003cli\u003eHTTP 404 codes/pages or other HTTP non-200 codes/pages.\u003c/li\u003e\n\u003cli\u003eFingerprinting/banner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eDisclosure of known public files or directories (e.g. robots.txt).\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eCSRF on forms that are available to anonymous users (e.g. the contact form).\u003c/li\u003e\n\u003cli\u003eCSRF attacks that require knowledge of the CSRF token (e.g. attacks involving a local machine).\u003c/li\u003e\n\u003cli\u003eLogout Cross-Site Request Forgery.\u003c/li\u003e\n\u003cli\u003eContent spoofing.\u003c/li\u003e\n\u003cli\u003ePresence of application or web browser ‘autocomplete’ or ‘save password’ functionality.\u003c/li\u003e\n\u003cli\u003eLack of secure/HTTP-only flags on non-sensitive cookies.\u003c/li\u003e\n\u003cli\u003eLack of security speed bump when leaving the site.\u003c/li\u003e\n\u003cli\u003eLogin or forgot password page brute force and account lockout not enforced.\u003c/li\u003e\n\u003cli\u003eSSL/TLS Issues, e.g.\n\n\u003cul\u003e\n\u003cli\u003eSSL Attacks such as BEAST, BREACH, and Renegotiation attacks.\u003c/li\u003e\n\u003cli\u003eSSL Forward secrecy not enabled.\u003c/li\u003e\n\u003cli\u003eSSL weak/insecure cipher suites.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eExpired certificates or certificates with a long expiration time.\u003c/li\u003e\n\u003cli\u003eSelf-XSS reports will not be accepted.\n\n\u003cul\u003e\n\u003cli\u003eSimilarly, any XSS requiring local access (i.e., user-agent header injection) will not be accepted. The only exception will be if you can show a working off-path MiTM attack that will trigger the XSS.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerabilities limited to old browsers will not be accepted (i.e. \"this exploit only works in IE6/IE7\").\u003c/li\u003e\n\u003cli\u003eKnown vulnerabilities in used libraries (e.g. jQuery) - unless you can prove exploitability.\u003c/li\u003e\n\u003cli\u003eAny source code disclosure.\u003c/li\u003e\n\u003cli\u003eInformation disclosure of non-confidential information (e.g. issue ID, project ID).\u003c/li\u003e\n\u003cli\u003eSecrets such as API keys or passwords obtained from external aggregation/indexed data sources (e.g. dehashed.com or intelx.io).\u003c/li\u003e\n\u003cli\u003eNPM name squatting is not considered a valid finding unless the package name is referenced as a dependancy by at least one octopus NPM package\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eTesting is only authorised on the targets listed as in-scope. Any domain/property of Octopus not listed in the targets section is out of scope. This includes any/all products not listed above. If you happen to identify a security vulnerability on a target that is not in-scope but that demonstrably belongs to Octopus, it may be reported to this program and is appreciated - but will ultimately be marked as 'not applicable' and will not be eligible for monetary or points-based compensation.\u003c/p\u003e\n\n\u003ch3\u003eOther Rules\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eReports need to be submitted in plain text (associated pictures/videos are fine as long as they're in standard formats and are accompanied by a plain text report). Non-plain text reports (e.g. PDF, DOCX) will be asked to be resubmitted in plain text.\u003c/li\u003e\n\u003cli\u003eGrants/awards are at the discretion of Octopus Deploy, and we withhold the right to grant, modify or deny grants.\u003c/li\u003e\n\u003cli\u003ePlease, no social engineering, phishing or unauthorised access to infrastructure.\u003c/li\u003e\n\u003cli\u003ePlease don’t test the physical security of Octopus Deploy offices, employees, equipment, etc.\u003c/li\u003e\n\u003cli\u003eThis bounty follows Bugcrowd’s standard disclosure terms.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003ePublic Disclosure\u003c/h3\u003e\n\n\u003cp\u003eBefore publicly disclosing an issue, we require you to request our permission. Octopus Deploy will process requests for public disclosure on a per-report basis. Requests to publicly disclose an issue that has not yet been fixed for customers will be rejected.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"48bbd201-5e19-4515-97c1-683a63c49d34","name":"In Scope","targets":[{"id":"a7c8342e-a1e1-487b-8a2a-cd8aa1f89114","uri":"https://octopus.com/downloads","name":"Octopus Tentacle","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"dc2e0b7e-9518-494d-9369-377289e6509e","sortOrder":0},"sortOrder":0,"tags":[{"id":"9ffd297c-4781-4777-94cf-ef4e2ddda266","name":"C#","targetId":"a7c8342e-a1e1-487b-8a2a-cd8aa1f89114"},{"id":"70f8fc74-f147-45d5-8f56-9bff2f555bd7","name":".NET","targetId":"a7c8342e-a1e1-487b-8a2a-cd8aa1f89114"}],"recentChangeFlags":null},{"id":"a1d49228-0845-46cf-bb0b-d2864bf03ac8","uri":"https://octopus.com/downloads","name":"Octopus Server","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"8f2f5d3a-4116-4895-9853-8776b35e44a5","sortOrder":0},"sortOrder":0,"tags":[{"id":"9ffd297c-4781-4777-94cf-ef4e2ddda266","name":"C#","targetId":"a1d49228-0845-46cf-bb0b-d2864bf03ac8"},{"id":"70f8fc74-f147-45d5-8f56-9bff2f555bd7","name":".NET","targetId":"a1d49228-0845-46cf-bb0b-d2864bf03ac8"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"479c0ae7-f463-4e85-8ddb-db228cd11436","p1MaxCents":600000,"p1MinCents":600000,"p2MaxCents":300000,"p2MinCents":200000,"p3MaxCents":100000,"p3MinCents":50000,"p4MaxCents":30000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":6000,"max":6000},"2":{"min":2000,"max":3000},"3":{"min":500,"max":1000},"4":{"min":200,"max":300},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[{"id":"eaffeac1-4cce-4120-836d-7da3a784fd28","attachmentPath":"https://bugcrowd.com/engagements/octopus-deploy/attachments/eaffeac1-4cce-4120-836d-7da3a784fd28","name":"image-2021-03-18T20:27:05.652Z.png","filename":"image-2021-03-18T20:27:05.652Z.png","description":null,"icon":"fileImage","size":1205,"sizeLabel":"1.18 KB","uploadedAt":"8 Aug 2024","fileType":"Image","embedUrl":"https://bugcrowd.com/engagements/octopus-deploy/attachments/eaffeac1-4cce-4120-836d-7da3a784fd28"},{"id":"c96a7627-09f2-4e57-ad2a-8c7f20ba4b3c","attachmentPath":"https://bugcrowd.com/engagements/octopus-deploy/attachments/c96a7627-09f2-4e57-ad2a-8c7f20ba4b3c","name":"image-2021-03-18T20:26:11.238Z.png","filename":"image-2021-03-18T20:26:11.238Z.png","description":null,"icon":"fileImage","size":1205,"sizeLabel":"1.18 KB","uploadedAt":"8 Aug 2024","fileType":"Image","embedUrl":"https://bugcrowd.com/engagements/octopus-deploy/attachments/c96a7627-09f2-4e57-ad2a-8c7f20ba4b3c"}],"engagement":{"id":"08a9c0ef-12b0-490c-acdb-785a11f85e72","code":"octopus-deploy","state":"in_progress","endsAt":null,"bountyId":"a351e553-ecfc-4da6-b246-f979a57daf93","startsAt":"2021-03-25T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/35eb/fbe1/e04f925e/fd58ea5d8d6747881d2c627ecf5bb84f_octops.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2021-03-25T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/octopus-deploy","changelogs":"/engagements/octopus-deploy/changelog","submissions":null,"announcements":"/engagements/octopus-deploy/announcements","hallOfFame":"/engagements/octopus-deploy/hall_of_fames","crowdstream":null},"announcementsCount":2,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/octopus-deploy/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=octopus-deploy\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/octopus-deploy/engagement_subscribers","engagementChangelogsUrl":"/engagements/octopus-deploy/changelog","publishedAt":"2025-10-28T02:04:41.378Z","engagementChangelogUrl":"/engagements/octopus-deploy/changelog/e680db64-f4c3-4e11-bb1f-db7b32c2b905","createUserFeedbacksUrl":"/engagements/octopus-deploy/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}