{"id":"b99d1ef0-f64e-463b-9c35-e2a080e7ee8d","engagementId":"71ecc734-6e9d-4a3a-b604-120db20c104d","data":{"brief":{"id":"c2bbf351-cd05-49aa-bdff-527934193850","name":"Octopus","tagline":"Octopus Bug Bounty Program","description":"\u003cp\u003eOctopus Deploy invites you to test and help secure our primary publicly facing assets - focusing first on our primary web application. We appreciate your efforts and hard work in making the internet (and Octopus Deploy) more secure, and look forward to working with the researcher community to create a meaningful and successful bug bounty program. \u003c/p\u003e\n\n\u003cp\u003eGood luck and happy hunting!\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eWhat you should know before you start\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eEnsure that you use your @bugcrowdninja.com email address when you’re testing our assets, any use of other email addresses may be treated as malicious and blocked.\u003c/li\u003e\n\u003cli\u003eEnsure that you understand the targets, scopes, exclusions, and rules below. Please feel free to reach out and ask questions to clarify. We want you to feel as confident as possible.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings / Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority. Please see below for any deviations from the standard VRT.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eEmployees, Contractors, Interns, and immediate family members are not eligible to receive rewards\u003cbr\u003e\nfrom our public-facing bug bounty programs. This restriction exists because employees may have\u003cbr\u003e\naccess to internal systems, non-public information, or responsibilities that could create an actual,\u003cbr\u003e\npotential, or perceived conflict of interest. Employees who identify potential vulnerabilities must\u003cbr\u003e\nreport them internally to the Security Operations team via security@octopus.com.\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003cp\u003eTesting is only authorised on the targets listed as in-scope. \u003cem\u003eAny domain/property of Octopus not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTarget Info\u003c/h2\u003e\n\n\u003ch3\u003eCredentials:\u003c/h3\u003e\n\n\u003cp\u003ePlease sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://researcherdocs.bugcrowd.com/v2.0/docs/your-bugcrowdninja-email-address\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eWhen getting started, click the sign-in URL at \u003ca href=\"https://octopus.com/register?registerReturnUrl=%2Fsignin\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://octopus.com/register?registerReturnUrl=%2Fsignin\u003c/a\u003e and register there.\u003c/p\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cp\u003eUltimately, we want to allow our customers to have a safe environment in which to manage their accounts, access our documentation, and manage their instances. Therefore, we're interested in traditional web application vulnerabilities, as well as other vulnerabilities that can have a direct impact on our customers. Below is a list of some of the vulnerability classes that we are seeking reports for:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eServer-side Remote Code Execution (RCE)\u003c/li\u003e\n\u003cli\u003eServer-Side Request Forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eStored/Reflected Cross-site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eCross-site Request Forgery (CSRF)\u003c/li\u003e\n\u003cli\u003eSQL Injection (SQLi)\u003c/li\u003e\n\u003cli\u003eXML External Entity Attacks (XXE)\u003c/li\u003e\n\u003cli\u003eAccess Control Vulnerabilities (Insecure Direct Object Reference issues, etc)\u003c/li\u003e\n\u003cli\u003ePath/Directory Traversal Issues\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eOut of Scope and Other Exclusions\u003c/h3\u003e\n\n\u003cp\u003eTo be as clear as possible, the following are \u003cem\u003ealso out of scope for testing\u003c/em\u003e:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSubdomain takeover.\u003c/li\u003e\n\u003cli\u003eWAF Bypasses (Octopus is currently reworking their WAF and not accepting any bypasses at this time).\u003c/li\u003e\n\u003cli\u003eSecrets such as API keys or passwords obtained from external aggregation/indexed data sources (e.g. dehashed.com and intelx.io).\u003c/li\u003e\n\u003cli\u003eOur self-hosted Octopus Deploy product, including its authentication and authorisation plugins.\u003c/li\u003e\n\u003cli\u003eOur cloud-hosted Octopus Deploy product.\u003c/li\u003e\n\u003cli\u003eAny of our closed or open-source tooling, build chain, public-facing repositories, email and IM servers, social media accounts, or third-party SaaS products that we use to deliver our services.\nBlind XSS must not return any user data you do not have access to (e.g., screenshots and cookies you don't own).\n\n\u003cul\u003e\n\u003cli\u003eWhen testing, please use the least invasive test possible (e.g. calling a 1x1 image or a nonexistent page on your web server).\u003c/li\u003e\n\u003cli\u003eWhen testing, please exercise caution if injecting on any form that may be publicly visible, such as forums. Before injection, please ensure your payload can be removed from the site. If it cannot be easily removed, please check with support@bugcrowd before performing the testing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003ePivoting and post-exploitation attacks are fine, particularly between test.octopus.com and test-account.octopus.com, so long as you aren’t attempting to destroy any infrastructure or data.\u003c/li\u003e\n\u003cli\u003eAny internal or development services.\u003c/li\u003e\n\u003cli\u003eThe use of automated scanners is prohibited.\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g. Stack Traces, application, and server errors).\u003c/li\u003e\n\u003cli\u003eFingerprinting/banner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eDisclosure of known public files or directories (e.g. robots.txt).\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eCSRF attacks that require knowledge of the CSRF token (e.g. attacks involving a local machine).\u003c/li\u003e\n\u003cli\u003eLogout Cross-Site Request Forgery.\u003c/li\u003e\n\u003cli\u003eContent spoofing.\u003c/li\u003e\n\u003cli\u003eThe presence of an application or web browser with \"autocomplete\" or \"save password\" functionality.\u003c/li\u003e\n\u003cli\u003eLack of Secure/HTTPOnly flags on non-sensitive Cookies.\u003c/li\u003e\n\u003cli\u003eLack of Security Speed Bump when leaving the site.\u003c/li\u003e\n\u003cli\u003eLog in or Forgot Password page brute force and account lockout not enforced.\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers, specifically (https://www.owasp.org/index.php/List_of_useful_HTTP_headers). For example:\n\n\u003cul\u003e\n\u003cli\u003eStrict-Transport-Security.\u003c/li\u003e\n\u003cli\u003eX-Frame-Options.\u003c/li\u003e\n\u003cli\u003eX-XSS-Protection.\u003c/li\u003e\n\u003cli\u003eX-Content-Type-Options.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy, X-Content-Security-Policy, X-WebKit-CSP.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy-Report-Only.\u003c/li\u003e\n\u003cli\u003eCache-Control and Pragma.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSSL/TLS Issues. For example:\n\n\u003cul\u003e\n\u003cli\u003eSSL Attacks such as BEAST, BREACH, and Renegotiation attacks.\u003c/li\u003e\n\u003cli\u003eSSL Forward secrecy not enabled.\u003c/li\u003e\n\u003cli\u003eSSL weak/insecure cipher suites.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eNo load testing (DoS/DDoS, etc) is allowed on the test websites.\u003c/li\u003e\n\u003cli\u003eSelf-XSS reports will not be accepted.\n\n\u003cul\u003e\n\u003cli\u003eAny XSS requiring local access (e.g., User-Agent Header injection) will not be accepted. The only exception is if you can show a working off-path MiTM attack that will allow the XSS to trigger.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerabilities limited to old browsers will not be accepted (e.g. \"this exploit only works in IE6/IE7\").\u003c/li\u003e\n\u003cli\u003eKnown vulnerabilities in used libraries (e.g. jQuery) unless you can prove exploitability.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect SPF records of any kind.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect DMARC records of any kind.\u003c/li\u003e\n\u003cli\u003eAny source code disclosure.\u003c/li\u003e\n\u003cli\u003eInformation disclosure of non-confidential information (e.g. issue ID, project ID).\u003c/li\u003e\n\u003cli\u003eEmail bombing.\u003c/li\u003e\n\u003cli\u003eRequest flooding (e.g. pixel flooding(we consider this a DoS attempt)).\u003c/li\u003e\n\u003cli\u003eTesting rate limits.\u003c/li\u003e\n\u003cli\u003eSession cookies for https://account.octopus.com will be valid for up to 10 minutes after logging out. Please do not report on any session fixation/management vulnerabilities unless you can show an account takeover after 10 minutes.\u003c/li\u003e\n\u003cli\u003ei.octopus.com contains a large number of files that are intended to be public.  This includes but is not limited to files that are referenced \u003ca href=\"https://octopus.com/company/trust\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e (such as tax residency, W8-BEN-E form, bank attestation documents etc)  on our trust resources page.  If a document is identified that you believe does not fall into this category and should be bought to our attention - please make a submission and it will be reviewed.\u003c/li\u003e\n\u003cli\u003eNPM name squatting is not considered a valid finding unless the package name is referenced as a dependancy by at least one octopus NPM package\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eTesting is only authorised on the targets listed as in-scope. Any domain/property of Octopus not listed in the targets section is out of scope, including any/all subdomains not listed above. If you identify a security vulnerability on a not-in-scope target that demonstrably belongs to the Octopus organisation, you can report it to this program. However, while it is appreciated, it will ultimately be marked as \"not applicable\" and not eligible for monetary or points-based compensation.\u003c/p\u003e\n\n\u003ch3\u003eOther Rules\u003c/h3\u003e\n\n\u003cp\u003eYou must ensure that your testing does not affect customer data in any way. Please ensure that you're being non-destructive while testing.\u003cbr\u003e\nIn addition to the above, customer instances are not to be accessed in any way (i.e., no customer data is to be accessed, and customer credentials are not to be used or \"verified\").\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIf you believe you have found sensitive customer data (e.g., login credentials, API keys, etc.) or a way to access customer data (e.g., through a vulnerability), report it, but do not attempt to validate whether/that it works successfully.\u003c/li\u003e\n\u003cli\u003eUse of any automated vulnerability scanners is prohibited.\u003c/li\u003e\n\u003cli\u003eReports must be submitted in plain text (associated pictures/videos are fine as long as they're in standard formats). Non-plain text reports (e.g. PDF and DOCX) will be asked to be resubmitted in plain text.\nGrants/awards are at Octopus Deploy's discretion, and we withhold the right to grant, modify, or deny grants.\u003c/li\u003e\n\u003cli\u003ePlease do not use social engineering, phishing, or unauthorised access to infrastructure.\u003c/li\u003e\n\u003cli\u003ePlease do not test the physical security of Octopus Deploy offices, employees, equipment, etc.\u003c/li\u003e\n\u003cli\u003eThis bounty follows Bugcrowd’s standard disclosure terms.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003ePublic Disclosure\u003c/h3\u003e\n\n\u003cp\u003eBefore publicly disclosing an issue, we require that you first request permission from us. Octopus Deploy will process requests for public disclosure on a per-report basis. Requests to publicly disclose an issue that has not yet been fixed for customers will be rejected.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eSafe Harbor:\u003c/h3\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorised in accordance with the Computer Fraud and Abuse Act (CFAA) (and similar state laws), and we will not initiate or support legal action against you for accidental, good-faith violations of this policy.\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls.\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy.\u003c/li\u003e\n\u003cli\u003eLawful and helpful to the overall security of the Internet and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eExpected to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"444ddc7f-ee00-45ff-b126-79cae2234abb","name":"In Scope","targets":[{"id":"117aead5-bca8-4284-bd25-0bf0a94482e3","uri":"","name":"*.octopus.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"fe8fc539-7a05-4830-816d-d1d0a5896f58","sortOrder":0},"sortOrder":0,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"117aead5-bca8-4284-bd25-0bf0a94482e3"},{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"117aead5-bca8-4284-bd25-0bf0a94482e3"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"117aead5-bca8-4284-bd25-0bf0a94482e3"}],"recentChangeFlags":null},{"id":"e8013f2e-02b6-41d9-b626-b74f8e7b90ca","uri":"https://github.com/OctopusDeploy","name":"Octopus Deploy Git Repo","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"bc1e0339-51cc-43de-b150-588efee5c03c","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e8013f2e-02b6-41d9-b626-b74f8e7b90ca"},{"id":"d58504e3-97f9-45ef-95aa-4a413a07190c","name":"Static Code Analysis","targetId":"e8013f2e-02b6-41d9-b626-b74f8e7b90ca"},{"id":"e6a92521-9abd-43e3-90a3-9c7b1b72f12a","name":"Code review","targetId":"e8013f2e-02b6-41d9-b626-b74f8e7b90ca"}],"recentChangeFlags":null},{"id":"ae59e48c-9c52-4f11-95f2-027afc1e3bb5","uri":"https://octopus.com","name":"octopus.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"9e2a4a9b-54c2-4b7b-be64-662510bc5cce","sortOrder":0},"sortOrder":0,"tags":[{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"ae59e48c-9c52-4f11-95f2-027afc1e3bb5"},{"id":"68da3fae-5355-463e-8442-9a5016b1bda0","name":"ASP.NET","targetId":"ae59e48c-9c52-4f11-95f2-027afc1e3bb5"},{"id":"70f8fc74-f147-45d5-8f56-9bff2f555bd7","name":".NET","targetId":"ae59e48c-9c52-4f11-95f2-027afc1e3bb5"},{"id":"b6333057-ce1f-4205-bcb6-ce56be83543b","name":"Microsoft IIS","targetId":"ae59e48c-9c52-4f11-95f2-027afc1e3bb5"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ae59e48c-9c52-4f11-95f2-027afc1e3bb5"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"479c0ae7-f463-4e85-8ddb-db228cd11436","p1MaxCents":600000,"p1MinCents":600000,"p2MaxCents":300000,"p2MinCents":200000,"p3MaxCents":100000,"p3MinCents":50000,"p4MaxCents":30000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003ePlease note that dependencies with known issues within the GitHub are not considered valid without a working proof of concept that affects the actual platform. In addition, API keys on their own are not considered valid. In order to have a valid leaked API key, the domain URL must be referencing an Octopus domain that fits *.octopus.app. Any API keys with localhost or test within their name are considered invalid.\u003c/p\u003e","rewardRangeData":{"1":{"min":6000,"max":6000},"2":{"min":2000,"max":3000},"3":{"min":500,"max":1000},"4":{"min":200,"max":300},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"a7637142-53e1-48b5-9452-0289587df061","name":"Out of scope targets","targets":[{"id":"1785ff6f-2a1d-4755-b47f-ae46faf63783","uri":"","name":" partners.octopus.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"dc8de3f1-a12d-4540-b8dc-d2a841d49c09","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"5e0fd47d-0bfe-4347-92eb-b640cd69123c","uri":null,"name":"*.octopus.app","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d6732000-b651-410d-b8cd-66c0b4bd29f0","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"5e0fd47d-0bfe-4347-92eb-b640cd69123c"}],"recentChangeFlags":null},{"id":"f319331d-982a-4202-83b9-6b1c2c93e95b","uri":"","name":"artifactorysample.octopus.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d54cfc22-4f98-45b0-bf55-1ce90100da36","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"70deefc9-e797-4e08-a05b-8afb451d7c0f","uri":"","name":"bamboosample.octopus.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"9baac406-d31b-4b25-a5e2-5735194acbc5","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"20844a77-0de8-4e2a-91a4-0a2248cbc1e2","uri":"","name":"jenkinssample.octopus.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c53e0957-362d-4d18-9040-74d40244cd84","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"855fe80f-3887-4b1e-a1b5-d0a672a0221c","uri":"","name":"teamcitysample.octopus.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"34202946-ef20-452c-a38b-c50e2eb5f028","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"68c19a59-75e6-4296-92ef-c838132110b1","uri":"","name":"nexussample.octopus.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7447053f-f4b5-460f-b96e-cbbc4f11d936","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"a1c034c1-6b6f-47a7-9186-ef331cafc70d","uri":"","name":"myget.octopus.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7c21b8c4-a214-4f88-9871-320d45945566","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"7aa0b590-a8b2-49cf-8394-38a9666db30b","uri":"","name":"trust.octopus.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ca8cf62e-ab80-42da-bf63-c130ca2763d0","sortOrder":8},"sortOrder":8,"tags":null,"recentChangeFlags":null},{"id":"f6f31c2d-b596-4083-bf8f-a409d7b6f637","uri":"","name":"i.octopus.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f426ae16-a5ce-47b5-9906-72d4c5b6fb27","sortOrder":9},"sortOrder":9,"tags":null,"recentChangeFlags":null},{"id":"b94ed1ad-e7c9-4555-b554-e82bdcdf9485","uri":"","name":"ir.octopus.com","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9105d7fa-58d5-44a7-a888-e3c0e9b54c9a","sortOrder":10},"sortOrder":10,"tags":null,"recentChangeFlags":null},{"id":"3ecb1ee1-fab5-447b-97a4-e5e1bba74071","uri":null,"name":"shop.octopus.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"12ad424c-db59-434d-85f3-e0cb883d4eab","sortOrder":11},"sortOrder":11,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"3ecb1ee1-fab5-447b-97a4-e5e1bba74071"}],"recentChangeFlags":["entirely_new"]}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eTargets in this list are OUT OF SCOPE.  Please also review the brief information below for more details, it contains important information and also lists further areas that are considered out of scope for this bounty.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"71ecc734-6e9d-4a3a-b604-120db20c104d","code":"octopus-og","state":"in_progress","endsAt":null,"bountyId":"a351e553-ecfc-4da6-b246-f979a57daf93","startsAt":"2019-05-28T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/35eb/fbe1/e04f925e/fd58ea5d8d6747881d2c627ecf5bb84f_octops.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2019-05-28T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/octopus-og","changelogs":"/engagements/octopus-og/changelog","submissions":null,"announcements":"/engagements/octopus-og/announcements","hallOfFame":"/engagements/octopus-og/hall_of_fames","crowdstream":"/engagements/octopus-og/crowdstream"},"announcementsCount":13,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/octopus-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=octopus-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/octopus-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/octopus-og/changelog","publishedAt":"2026-09-07T08:41:14.292Z","engagementChangelogUrl":"/engagements/octopus-og/changelog/b99d1ef0-f64e-463b-9c35-e2a080e7ee8d","createUserFeedbacksUrl":"/engagements/octopus-og/feedbacks","engagementCrowdstreamUrl":"/engagements/octopus-og/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}