{"id":"d4dc2398-db8d-4b89-9f7f-0aae75251307","engagementId":"f2f9e672-46c8-4d45-8dd0-ec606fcd1ca4","data":{"brief":{"id":"abfb7524-f097-475a-9801-a3be0f3812bc","name":"Okta","tagline":"Cloud Identity and Mobility Management Service","description":"\u003cp\u003eWe believe community researcher participation and building a secure foundation plays an integral role in protecting our customers and their data. We appreciate all security submissions and strive to respond in an expedient manner.\u003c/p\u003e\n\n\u003cp\u003eOkta is a cloud-based identity service that connects people to their applications from any device, anywhere, anytime. The Okta Identity Cloud provides directory services, single sign-on, strong authentication, provisioning, mobile device management and API access management. It comes with built-in reporting, and integrates deeply with cloud, mobile and on-premises applications, directories and identity management systems.\u003c/p\u003e","industryTagId":"95db792c-091b-4c81-8d72-b09b1d065f09","targetsOverview":"\u003ch3\u003eAI-generated content\u003c/h3\u003e\n\n\u003cp\u003eWe \u003cstrong\u003edo not\u003c/strong\u003e accept reports that contain \u003cstrong\u003elow-effort\u003c/strong\u003e or \u003cstrong\u003eAI-generated content\u003c/strong\u003e. Submissions must demonstrate original analysis, clear understanding of the issue, and actionable detail. Reports lacking meaningful human input will be rejected. \u003cstrong\u003eRepeat offenders will be removed from the program.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003eRedeem Credentials\u003c/h2\u003e\n\n\u003cp\u003eAt the bottom of the program brief, click on \"Get Credentials\" to retrieve 2 sets of credentials.\u003c/p\u003e\n\n\u003ch2\u003eDO THIS FIRST!\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eChange the email address associated with the provided users so that you can handle your own password resets\u003c/li\u003e\n\u003cli\u003eCreate at least 2 other Super Admins in each ORG for resetting locked accounts and handling account problems.\u003c/li\u003e\n\u003cli\u003eFollow the steps to setup and enforce MFA on each Login under \"Required MFA Configuration\"\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eFocus Areas per Product\u003c/h2\u003e\n\n\u003ch4\u003eFocus Areas for Okta\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://developer.okta.com/reference/okta_expression_language/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eOkta Expression Language\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://support.okta.com/help/Documentation/Knowledge_Article/Connecting-to-Okta-using-the-LDAP-Interface-1268627519\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eLDAP as a Service\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAuthentication Protocol Vulnerabilities (e.g. \u003ca href=\"https://developer.okta.com/standards/SAML/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSAML\u003c/a\u003e, \u003ca href=\"https://developer.okta.com/docs/api/resources/oidc\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eOAuth \u0026amp; OIDC\u003c/a\u003e,\u003ca href=\"https://developer.okta.com/authentication-guide/social-login/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSocial Auth\u003c/a\u003e )\u003c/li\u003e\n\u003cli\u003eXXE within the massive amount of XML data we accept\u003c/li\u003e\n\u003cli\u003eOkta Browser Plugin (IE / Firefox / Chrome)\u003c/li\u003e\n\u003cli\u003eCross-Org Access / Multi-Tenancy Vulnerabilities\u003c/li\u003e\n\u003cli\u003ePrivileged (Horizontal / Vertical) Escalation\u003c/li\u003e\n\u003cli\u003eAll on-premise Agents (e.g. LDAP / AD / OPP / Radius / RSA)\u003c/li\u003e\n\u003cli\u003eOkta Verify (iOS / Android)\u003c/li\u003e\n\u003cli\u003eXSS and other Top 10 Issue such as Open Redirection and CSRF on sensitive page actions\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eFocus Areas for Okta Personal\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eGaining access to Okta Personal Admin Dashboard or Identity Provider Dashboard\n\n\u003cul\u003e\n\u003cli\u003eIf you gain access, do not proceed further or navigate. Immediately stop all testing and report.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eBreaking Okta Personal’s crypto and retrieving users data\u003c/li\u003e\n\u003cli\u003ePush notification flows (\u003cstrong\u003e\u003cem\u003eunavailable at the moment\u003c/em\u003e\u003c/strong\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://support.oktapersonal.com/article/48-share-apps\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSharing functionality\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInput validation issues\u003c/li\u003e\n\u003cli\u003eMobile intents\u003c/li\u003e\n\u003cli\u003eImport + Export applications\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eFocus Areas for Okta Workflows\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eAbility to perform SSRF with Flo cards\u003c/li\u003e\n\u003cli\u003eAbility to provision and deprovision Workflow orgs\u003c/li\u003e\n\u003cli\u003ePerforming Flo actions across orgs\u003c/li\u003e\n\u003cli\u003eViewing sensitive information across orgs\u003c/li\u003e\n\u003cli\u003eAbility to escape from sandbox using API Endpoint \u0026amp; Return Raw\u003c/li\u003e\n\u003cli\u003eBypassing maximum 5 active flow limit and running the flows\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch5\u003eWorkflows Roles and Permissions\u003c/h5\u003e\n\n\u003cp\u003eRefer to the roles and permissions for Workflows here\u003cbr\u003e\n\u003ca href=\"https://help.okta.com/wf/en-us/content/topics/workflows/access-control/access-control-roles.htm\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://help.okta.com/wf/en-us/content/topics/workflows/access-control/access-control-roles.htm\u003c/a\u003e\u003c/p\u003e\n\n\u003ch4\u003eFocus Areas for Okta Privileged Access\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eASA Client / Agents\u003c/li\u003e\n\u003cli\u003eSecrets\u003c/li\u003e\n\u003cli\u003eResource Administration\u003c/li\u003e\n\u003cli\u003eSecurity Administration\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eFocus Areas for Advanced Server Access\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eASA Client / Agents\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eFocus Areas for AtSpoke (Okta Access Requests)\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eConfiguration List \u003ca href=\"https://help.okta.com/en-us/content/topics/identity-governance/access-requests/ar-config-sublist.htm\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCreate a configuration list\u003c/a\u003e. Ability to bypass resource restrictions imposed by configuration lists\u003c/li\u003e\n\u003cli\u003eCreate a Request Type \u003ca href=\"https://help.okta.com/en-us/content/topics/identity-governance/access-requests/ar-create-request-type.htm\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCreate a request type\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eCreate and manage requests \u003ca href=\"https://help.okta.com/en-us/content/topics/identity-governance/access-requests/ar-request-create.htm\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCreate requests\u003c/a\u003e. Ability to modify critical fields of an access request (like assignee, approver, resource, etc)\u003c/li\u003e\n\u003cli\u003eAccess request integrations \u003ca href=\"https://help.okta.com/en-us/content/topics/identity-governance/access-requests/ar-integrations.htm\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAccess Requests Integrations\u003c/a\u003e. Ability to execute injection attacks from integrations: Jira, ServiceNow, Slack, Microsoft Teams\u003c/li\u003e\n\u003cli\u003eExport data from access requests \u003ca href=\"https://help.okta.com/en-us/content/topics/identity-governance/access-requests/ar-export.htm\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eExport data from Access Requests\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eFile Upload \u003ca href=\"https://iamse.blog/2023/08/08/oig-access-requests-can-i-attach-a-file/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eOIG Access Requests - Can I Attach a File?\u003c/a\u003e\n-OIDC (custom client implementation)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eAdvisory Note for AtSpoke\u003c/h4\u003e\n\n\u003cp\u003eFor reference, here is a table of the different privileges of users in AtSpoke. This table may change at any time at the discretion of Okta. This is not an exhaustive list and each submission will be evaluated.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e In this table,\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e“your team” is a team of which the user is a member, and \u003c/li\u003e\n\u003cli\u003e“another team” is a team of which the user is not a member.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eAction\u003c/th\u003e\n\u003cth\u003eAdmin\u003c/th\u003e\n\u003cth\u003eTeam Member\u003c/th\u003e\n\u003cth\u003eRegular User\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eView a public request\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eTake actions on a public request\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eView a private request you're \u003cstrong\u003esubscribed to\u003c/strong\u003e\n\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eTake actions on a private request you're \u003cstrong\u003esubscribed to\u003c/strong\u003e\n\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eView a private request on \u003cstrong\u003eyour\u003c/strong\u003e team that you're \u003cstrong\u003enot subscribed to\u003c/strong\u003e\n\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eTake actions on a private request on \u003cstrong\u003eyour\u003c/strong\u003e team that you're \u003cstrong\u003enot subscribed to\u003c/strong\u003e\n\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eView a private request on \u003cstrong\u003eanother\u003c/strong\u003e team that you’re \u003cstrong\u003enot subscribed to\u003c/strong\u003e\n\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eEdit a private request on \u003cstrong\u003eanother\u003c/strong\u003e team that you’re \u003cstrong\u003enot subscribed to\u003c/strong\u003e\n\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eView all other users’ profile information\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eView all (public and invite-only) teams\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eJoin a public team\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eEdit a public team\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eEdit \u003cstrong\u003eyour\u003c/strong\u003e invite-only team\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eJoin \u003cstrong\u003eanother\u003c/strong\u003e invite-only team\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eEdit \u003cstrong\u003eanother\u003c/strong\u003e invite-only team\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eRemove a team member from \u003cstrong\u003eyour\u003c/strong\u003e team\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eRemove a team member from \u003cstrong\u003eanother\u003c/strong\u003e team\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eCreate request types on \u003cstrong\u003eyour\u003c/strong\u003e team\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eCreate request types on \u003cstrong\u003eanother\u003c/strong\u003e team\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eUpdate integrations (install Slack, etc.)\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e❌\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eView Visible Segments which includes which users are in groups pushed to Access Requests\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003ctd\u003e✅\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003ch3\u003eReport Criteria\u003c/h3\u003e\n\n\u003cp\u003eAll submissions must be in the following format:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre class=\"highlight plaintext\"\u003e\u003ccode\u003eDescription\n\n\nBusiness Impact (how does this affect Okta?)\n\n\nWorking proof of concept\n\n\nDiscoverability (how likely is this to be discovered)\n\n\nExploitability (how likely is this to be exploited)\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003ch2\u003ePayout\u003c/h2\u003e\n\n\u003cp\u003eEligible reports will be awarded based on severity, which will be determined by Okta at its sole discretion. \u003c/p\u003e\n\n\u003cp\u003eFor payout ranges, refer to the In-Scope targets above.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eKeep in mind that no two bugs are created equal. These payouts define general guidelines. The Okta Security team will determine the nature and impact of the bugs to identify the appropriate payouts around these guidelines. Awards are granted entirely at the discretion of Okta.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003eRules of Engagement\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eEmployees and relatives are \u003cstrong\u003eNOT\u003c/strong\u003e eligible for a bounty\u003c/li\u003e\n\u003cli\u003eNo automated scanning \u003c/li\u003e\n\u003cli\u003eNo DoS - Amazon prohibits this activity and testing cluster not scaled for these attacks\u003c/li\u003e\n\u003cli\u003eAny sort of DoS against Okta Workflows is strictly out of scope\u003c/li\u003e\n\u003cli\u003eAny sort of automation against Okta Workflows is strictly out of scope\u003c/li\u003e\n\u003cli\u003eLimit AD / LDAP Imports to 1000 users \u0026amp; groups\u003c/li\u003e\n\u003cli\u003eDo \u003cem\u003eNOT\u003c/em\u003e contact Okta support or helpdesk for bugbounty related concerns - please contact bugcrowd support\u003c/li\u003e\n\u003cli\u003ePublicly-known zero-day vulnerabilities will not be considered for eligibility until more than 30 days have passed since patch availability\u003c/li\u003e\n\u003cli\u003eYou are testing on production systems. As such, please refrain from the use of scanning engines or anything that can affect load on our production servers. In addition, use common sense judgement to not do anything to affect our systems in general.\u003c/li\u003e\n\u003cli\u003eCustomer data must not be affected in any way as a result of your testing.\u003c/li\u003e\n\u003cli\u003eCustomer instances must not be accessed in any way.\u003c/li\u003e\n\u003cli\u003eThe use of any automated tools or scanners is prohibited.\u003c/li\u003e\n\u003cli\u003eDo NOT perform any type of burp scans or scanners.\u003c/li\u003e\n\u003cli\u003eDo not conduct non-technical attacks such as social engineering, phishing or unauthorized access to infrastructure.\u003c/li\u003e\n\u003cli\u003eDo not test the physical security of Auth0 offices, employees, equipment, etc.\u003c/li\u003e\n\u003cli\u003eIf you gain access to servers, do not attempt to pivot. Stop all testing and report.\u003c/li\u003e\n\u003cli\u003eFor Okta Personal, if you gain access to the Admin Dashboard or Identity Provider Dashboard, stop all testing and report.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut Of Scope\u003c/h2\u003e\n\n\u003ch4\u003eThe following finding types are specifically \u003cem\u003eexcluded\u003c/em\u003e from the bounty:\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eSOQL Injections\u003c/li\u003e\n\u003cli\u003eAbandoned/unclaimed domains, domain squatting, link rot, social media hijacking etc\u003c/li\u003e\n\u003cli\u003eAll subdomain takeovers unless it is immediately critical\u003c/li\u003e\n\u003cli\u003eInvalidating User Sessions\n\n\u003cul\u003e\n\u003cli\u003eRefer to Invalidating Sessions section\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eEXIF Metadata\u003c/li\u003e\n\u003cli\u003eHTML Email Injection\n\n\u003cul\u003e\n\u003cli\u003eRefer to HTML Injection section\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eHTML Injection\n\n\u003cul\u003e\n\u003cli\u003eRefer to HTML Injection section\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eHost Header Redirect without user impact\u003c/li\u003e\n\u003cli\u003eOkta Mobility Management (OMM) (Low severity vulns will be rejected)\u003c/li\u003e\n\u003cli\u003eHTTP 404 codes/pages or other HTTP non-200 codes/pages.\u003c/li\u003e\n\u003cli\u003eFingerprinting / banner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eDisclosure of known public files or directories, (e.g. robots.txt).\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eCSRF on forms that are available to anonymous users (e.g. login or contact form).\u003c/li\u003e\n\u003cli\u003eLogout / Login Cross-Site Request Forgery (logout CSRF).\u003c/li\u003e\n\u003cli\u003ePresence of application or web browser ‘autocomplete’ or ‘save password’ functionality.\u003c/li\u003e\n\u003cli\u003eLack of Security Speedbump when leaving the site.\u003c/li\u003e\n\u003cli\u003eNo Captcha / Weak Captcha / Captcha Bypass\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force and account lockout not enforced\u003c/li\u003e\n\u003cli\u003eHTTP method enabled\n\n\u003cul\u003e\n\u003cli\u003eOPTIONS, PUT,GET,DELETE,INFO\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eWebServer Type disclosures\u003c/li\u003e\n\u003cli\u003eSocial engineering of our service desk, employees or contractors\u003c/li\u003e\n\u003cli\u003ePhysical attacks against Okta's offices and data centers\u003c/li\u003e\n\u003cli\u003eRequiring a user's physical device\u003c/li\u003e\n\u003cli\u003eError messages with non-sensitive data\u003c/li\u003e\n\u003cli\u003eNon-application layer Denial of Service or DDoS\u003c/li\u003e\n\u003cli\u003eLack of HTTP Only / SECURE flag for cookies\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration\n\n\u003cul\u003e\n\u003cli\u003evia Login Page error message\u003c/li\u003e\n\u003cli\u003evia Forgot Password error message\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers, specifically (https://www.owasp.org/index.php/List_of_useful_HTTP_headers), e.g.\n\n\u003cul\u003e\n\u003cli\u003eStrict-Transport-Security\u003c/li\u003e\n\u003cli\u003eX-Frame-Options\u003c/li\u003e\n\u003cli\u003eX-XSS-Protection\u003c/li\u003e\n\u003cli\u003eX-Content-Type-Options\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy, X-Content-Security-Policy, X-WebKit-CSP\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy-Report-Only\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSPF / DMARC / DKIM Mail and Domain findings\u003c/li\u003e\n\u003cli\u003eEmail Rate Limiting or Spamming\u003c/li\u003e\n\u003cli\u003eDNSSEC Findings\u003c/li\u003e\n\u003cli\u003eCSV Issues\u003c/li\u003e\n\u003cli\u003eAV Scanning\u003c/li\u003e\n\u003cli\u003eSSL Issues, e.g.\n\n\u003cul\u003e\n\u003cli\u003eSSL Attacks such as BEAST, BREACH, Renegotiation attack\u003c/li\u003e\n\u003cli\u003eSSL Forward secrecy not enabled\u003c/li\u003e\n\u003cli\u003eSSL weak / insecure cipher suites\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eCookie Issues \n\n\u003cul\u003e\n\u003cli\u003eHTTPONLY\u003c/li\u003e\n\u003cli\u003eSECURE\u003c/li\u003e\n\u003cli\u003emultiple cookie setting\u003c/li\u003e\n\u003cli\u003eAnything to do with JSESSIONID\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eService Rate Limiting\u003c/li\u003e\n\u003cli\u003eUser or Org enumeration\u003c/li\u003e\n\u003cli\u003eSecurity Image Issues\u003c/li\u003e\n\u003cli\u003eBusiness Logic \u003cem\u003eREAD\u003c/em\u003e Issues\n\n\u003cul\u003e\n\u003cli\u003eE.G. Any Admin can see Another Admin's users, devices, or download reports\u003c/li\u003e\n\u003cli\u003eE.G. Read-Only Admin can see logs or other details\u003c/li\u003e\n\u003cli\u003eE.G. Mobile Admin can see Super User details\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eReference Information\u003c/h1\u003e\n\n\u003cp\u003e\u003ca href=\"https://developer.okta.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eOkta Public API References\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://support.okta.com/help\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eOkta Configuration \u0026amp; Support Site\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://support.okta.com/help/Documentation/Knowledge_Article/Install-and-Configure-the-Okta-Active-Directory-Agent-1597766701\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAD Agent\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://support.okta.com/help/Documentation/Knowledge_Article/Install-the-Okta-RADIUS-agent-1160955325\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eRadius Agent\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://support.okta.com/help/Documentation/Knowledge_Article/87604166-LDAP-Agent-Deployment-Guide\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eLDAP Agent Installation\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://support.okta.com/help/Documentation/Knowledge_Article/Connecting-to-Okta-using-the-LDAP-Interface-1268627519\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eLDAP as a Service\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://support.okta.com/help/Documentation/Knowledge_Article/Install-and-configure-the-Okta-IWAWeb-App-for-Desktop-SSO-291155157\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eDesktop SSO / IWA\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://support.okta.com/help/Documentation/Knowledge_Article/About-the-Okta-Browser-Plugin-1982645825\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBrowser Plugin\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://developer.okta.com/standards/SAML/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSAML\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://developer.okta.com/docs/api/resources/oidc\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eOAuth \u0026amp; OIDC\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://developer.okta.com/blog/2017/06/21/what-the-heck-is-oauth\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eOAuth Overview\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://developer.okta.com/authentication-guide/social-login/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSocial Auth\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003ePlease check current \u003ca href=\"https://support.okta.com/help/Documentation/Knowledge_Article/Current-Release-Status\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eRelease Notes\u003c/a\u003e to see what's new. New code is released weekly.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch3\u003eTheoretical Issues\u003c/h3\u003e\n\n\u003cp\u003eAny submissions suggesting that an issue \u003cstrong\u003ecould\u003c/strong\u003e lead to or has the potential to cause impact will be considered \u003cstrong\u003eOUT OF SCOPE\u003c/strong\u003e. You \u003cem\u003e\u003cstrong\u003eMUST\u003c/strong\u003e\u003c/em\u003e provide a complete proof of concept demonstrating the attack detailed in the submission.\u003c/p\u003e\n\n\u003ch2\u003eChaining Bugs\u003c/h2\u003e\n\n\u003cp\u003eChaining of bugs is not frowned upon in any way, we love to see clever exploit chains! However, if you have managed to compromise an Okta owned server we do not allow for escalations such as port scanning internal networks, privilege escalation attempts, attempting to pivot to other systems, etc. If you get access this level of access to a server please report it us and we will reward you with an appropriate bounty taking into full consideration the severity of what could be done. Chaining a CSRF vulnerability with a self XSS? Nice! Using AWS access key to dump sensitive info? Not cool.\u003c/p\u003e\n\n\u003ch2\u003eUnsure of a vuln?\u003c/h2\u003e\n\n\u003cp\u003eWe base all payouts on \u003cem\u003erisk\u003c/em\u003e \u003cstrong\u003eAND\u003c/strong\u003e \u003cem\u003eimpact\u003c/em\u003e - when in doubt the question always comes down to risk and impact (aka what can actually be done with the vulnerability and what is the consequence to Okta). If you can demonstrate why a finding has significant impact, then please submit. \u003c/p\u003e\n\n\u003cp\u003eAs an example: Let's say you can, as a limited admin, see logs that are not in your user role - What is the impact? If this allows you to compromise something else then please detail the full exploit chain and report. However if the only impact is reading logs.. then there is no need to report it as it would fall under - Business Logic \u003cem\u003eREAD\u003c/em\u003e issues.\u003c/p\u003e\n\n\u003cp\u003eAnother example: Let's say you can, as a limited admin, see a list of applications but you cannot access them - What is the impact? Are you able to utilize the appID and access contents (such as the secret, jwt, etc) of the application with another endpoint? Report it. However, if you're only able to see the list of applications and the names, there is no need to report it.\u003c/p\u003e\n\n\u003ch2\u003eAdditional Details\u003c/h2\u003e\n\n\u003ch3\u003eSimilar Bugs\u003c/h3\u003e\n\n\u003cp\u003eBugs of similar nature or root cause reported by the same person may be combined into one item, thus constituting only a single award.\u003c/p\u003e\n\n\u003ch3\u003eRequired MFA Configuration\u003c/h3\u003e\n\n\u003cp\u003eAll orgs are created with a minimal configuration and it's the customer's (your responsibility) to configure the environment to \u003cem\u003eenforce\u003c/em\u003e MFA enrollment \u003cem\u003eAND\u003c/em\u003e validation.\u003c/p\u003e\n\n\u003ch4\u003eCLASSIC Orgs\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eRequire MFA Enrollment\n\n\u003cul\u003e\n\u003cli\u003eGo to \u003ccode\u003eSecurity -\u0026gt; Multifactor -\u0026gt; Factor Enrollment\u003c/code\u003e and require enrollment to specific authenticators\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSet a factor to be required for all login\n\n\u003cul\u003e\n\u003cli\u003e\n\u003ccode\u003eSecurity -\u0026gt; Authentication Sign On : Default Policy\u003c/code\u003e\n\u003cstrong\u003eAdd Rule\u003c/strong\u003e\nSet to \u003ccode\u003eanywhere / all the time\u003c/code\u003e\nCHECK \u003ccode\u003ePrompt for Factor\u003c/code\u003e\nSelect \u003ccode\u003eEvery Time\u003c/code\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThis manual configuration above is required to fully enable MFA validation for users and admins within your Okta org\u003c/p\u003e\n\n\u003ch4\u003eOIE Orgs\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequire MFA Enrollment\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eGo to \u003ccode\u003eSecurity -\u0026gt; Authenticators -\u0026gt; Enrollment\u003c/code\u003e and require enrollment to specific authenticators\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSet a factor to be required for all login\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003ccode\u003eSecurity -\u0026gt; Global Session Policy\u003c/code\u003e\n\u003cstrong\u003eAdd Rule\u003c/strong\u003e\nSet to \u003ccode\u003eAny factor used to meet the Authentication Policy requirements\u003c/code\u003e\nMultifactor authentication (MFA) is \u003cstrong\u003eREQUIRED\u003c/strong\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eConfigure application sign on policies\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eSecurity -\u0026gt; Authentication Policies -\u0026gt; Add a policy\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eCreate new rules and add an application under the policy\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eFull MFA Bypass\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe above \"Required MFA Configuration\" must be added\u003c/li\u003e\n\u003cli\u003eIf applications are the target MFA must be required per-app with no exceptions\u003c/li\u003e\n\u003cli\u003eMFA Bypass would include mechanisms to avoid, remove, or compromise of MFA server side for a customer. \u003c/li\u003e\n\u003cli\u003eExamples of unacceptable submissions would include turning off MFA, changing MFA as the admin, changing MFA policies as the admin, bypassing local-only checks \u003c/li\u003e\n\u003cli\u003eRequiring compromised credentials, bruteforcing, and locking out the account will reduce severity and impact. The Okta org sign on policy must require MFA and the Enduser \u0026amp; Admin dashboard must require MFA. No social engineering or phishing. No theoretical attacks.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eBrowser Plugin Compromise\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eCritical browser plugin vulnerabilities would include a compromise of the entire plugin on any supported platform. Accepted, but not critical, issues would include single site reg-ex confusion, inappropriate interaction with the plugin from the target DOM, API vulnerabilities in usage or implementation for the os/browser. \u003c/li\u003e\n\u003cli\u003eExamples of unacceptable submissions would include directly modifying the plugin on the host, creating a fake plugin, theoretical issues that can not be reproduced.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eMobile App Critical Vulnerability\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eCritical mobile application vulnerabilities would include a compromise of the mobile application from the network, other apps on the device, 3rd party library vulnerabilities, or via accessible APIs. \u003c/li\u003e\n\u003cli\u003eExamples of unacceptable submissions would include enhancement recommendations, issues that are only exploitable on JailBroken / Rooted devices and do not work on un-modified equipment, and reports related to hooking, wrapping, or replacing the application.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eHTML Injection\u003c/h3\u003e\n\n\u003cp\u003eHTML Injection reports must demonstrate real security risk and impact. Reports demonstrating basic HTML payloads or payloads such as \u003ccode\u003e\u0026lt;h1\u0026gt;Test\u0026lt;/h1\u0026gt;\u003c/code\u003e, \u003ccode\u003e\u0026lt;form action=\"https://evil.com\"\u0026gt;\u003c/code\u003e, \u003ccode\u003e\u0026lt;a href=\"https://okta.com\u0026gt;test\u0026lt;/a\u0026gt;\u003c/code\u003e, etc, will be rejected as \u003ccode\u003eOut of scope\u003c/code\u003e. \u003cbr\u003e\nIn most cases, HTML injections can result into XSS and we encourage you to discover a bypass to our XSS validation.\u003c/p\u003e\n\n\u003ch3\u003eInvalidating Sessions\u003c/h3\u003e\n\n\u003cp\u003eBefore submitting any requests regarding invalidating user sessions due to changing passwords or performing password resets, ensure that you choose \"Sign me out of all other devices\" on the password change screen. This action will invalidate sessions on all other devices.\u003c/p\u003e\n\n\u003cp\u003eSubmissions concerning session invalidation for other applications (such as Workflows, AtSpoke, etc.) when resetting passwords, clearing user sessions, or terminating users in the Okta Admin Dashboard will be marked as not applicable (N/A). It's important to note that terminating a user's session using any of the mentioned methods will not affect any SAML/OIDC applications initiated by the user; their sessions will remain active until expiration.\u003c/p\u003e\n\n\u003cp\u003eOkta supports Service Provider-initiated (SP-initiated) logout for third-party SAML and OIDC applications. When a user clicks the sign-out button in applications like Workflows or AtSpoke, the application directs the browser to Okta, triggering an inbound logout request. This action signals to Okta that the user wishes to sign out of the application, and in response, Okta terminates the user's session.\u003c/p\u003e\n\n\u003cp\u003eAdditionally, there are plans to implement single log-out (SLO) in the future.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":"\u003cp\u003eIn addition to the above standard disclosure terms, by participating in this program, you're agreeing to abide by Okta's \u003ca href=\"https://www.okta.com/sites/default/files/Okta_Vulnerability_Disclosure_Policy.pdf\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eVulnerability Disclosure Policy\u003c/a\u003e and \u003ca href=\"https://www.okta.com/sites/default/files/VDP_Supplemental_Terms.pdf\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSupplemental Terms\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eThis bounty requires explicit permission to disclose the results of a submission.\u003c/strong\u003e\u003c/p\u003e"},"scope":[{"id":"afa28c91-ae9d-45a0-a778-6e45436655db","name":"Okta Personal","targets":[{"id":"674dc154-daf6-4d4b-95b2-03feb9f0a5ce","uri":"","name":"personal.trexcloud.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"34e5369d-bac6-4767-a3bd-f050b8c9e85e","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"674dc154-daf6-4d4b-95b2-03feb9f0a5ce"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"674dc154-daf6-4d4b-95b2-03feb9f0a5ce"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch2\u003eRegister for Okta Personal\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eGo to \u003ca href=\"https://personal.trexcloud.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://personal.trexcloud.com\u003c/a\u003e and sign up for an account. You \u003cem\u003e\u003cstrong\u003eMUST\u003c/strong\u003e\u003c/em\u003e use your @bugcrowdninja.com email address.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eInstructions\u003c/h2\u003e\n\n\u003ch3\u003eFor iOS\u003c/h3\u003e\n\n\u003cp\u003eOnce you register an Okta Personal account, you must install the Okta Personal application through the App Store. Once you open the application, you will need to activate \u003cstrong\u003edebug\u003c/strong\u003e mode.\u003c/p\u003e\n\n\u003cp\u003eFrom the main start page:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTap on \u0026quot;Okta Personal\u0026quot; 3 times\u003c/li\u003e\n\u003cli\u003eTap on the shield logo in the center 2 times\u003c/li\u003e\n\u003cli\u003eAt this point, \u0026quot;Let us secure what\u0026#39;s important to you\u0026quot; should be underlined\u003c/li\u003e\n\u003cli\u003eLong press \u0026quot;Let us secure what\u0026#39;s important to you\u0026quot;\u003c/li\u003e\n\u003cli\u003eSelect \u0026quot;Trex\u0026quot; as your Base URL\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIf the \u003cstrong\u003edebug\u003c/strong\u003e mode doesn\u0026#39;t show up, completely close out the application and retry.\u003c/p\u003e\n\n\u003ch3\u003eFor Android\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eGo to the link here \u003ca href=\"https://appdistribution.firebase.dev/i/4116040c826cc62f\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://appdistribution.firebase.dev/i/4116040c826cc62f\u003c/a\u003e\n\n\u003cul\u003e\n\u003cli\u003eIf the link above doesn\u0026#39;t work, try \u003ca href=\"https://appdistribution.firebase.dev/i/2f6eccc30f6a70eb\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://appdistribution.firebase.dev/i/2f6eccc30f6a70eb\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003eEnter your email address to receive the app download link.\u003c/li\u003e\n\u003cli\u003eFollow the instructions in the download link to install the app on an Android device.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eRecovery Key\u003c/h3\u003e\n\n\u003cp\u003eDuring the mobile application enrollment, a Recovery Key will be provided. Make sure to save the Recovery Key to access the dashboard with the browser.\u003c/p\u003e\n\n\u003ch3\u003ePush Notifications\u003c/h3\u003e\n\n\u003cp\u003eThe push notification functionality for the mobile applications are not working with the \u0026quot;Trex\u0026quot; env. Make sure to copy your Recovery Key to access your dashboard.\u003c/p\u003e\n\n\u003ch2\u003eReferences\u003c/h2\u003e\n\n\u003cp\u003e\u003ca href=\"https://support.oktapersonal.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eOkta Personal Documentation\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://www.okta.com/sites/default/files/2024-03/Okta%20Personal%20Technical%20Whitepaper-020124.pdf\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eOkta Personal Whitepaper\u003c/a\u003e\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"e1f75a01-8dd9-4c67-b334-fa8312bfacfa","name":"Okta Privileged Access","targets":[{"id":"0ef18093-315f-4fd0-8ef0-f186d4f4d607","uri":"","name":"bugcrowd-pam-###.oktapreview.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1e974230-6903-4b7a-835d-4a2418939a6e","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"e385a3ab-a2e8-4223-bd3f-5b2d5cde274a","uri":"","name":"bugcrowd-pam-###.pam.oktapreview.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"bf663e93-8cba-4982-8966-7ee29c5cca0a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"004c2c52-e6bc-45f6-860c-0352dc584e03","p1MaxCents":3500000,"p1MinCents":700000,"p2MaxCents":700000,"p2MinCents":300000,"p3MaxCents":300000,"p3MinCents":100000,"p4MaxCents":100000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch4\u003eRedeem Credentials\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eAt the bottom of the program brief, click on \u0026quot;Get Credentials\u0026quot; to retrieve 2 sets of credentials.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eDO THIS FIRST!\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eChange the email address associated with the provided users so that you can handle your own password resets\u003c/li\u003e\n\u003cli\u003eCreate at least 2 other Super Admins in each ORG for resetting locked accounts and handling account problems.\u003c/li\u003e\n\u003cli\u003eFollow the steps to setup and enforce MFA on each Login under \u0026quot;Required MFA Configuration\u0026quot;\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eAccessing Okta Privileged Access\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eGo to the Admin Dashboard and Applications\u003c/li\u003e\n\u003cli\u003eGo to Browse App Catalog and search for Okta Privileged Access. You will be asked to provide a team name which you should put your org name so \u003ccode\u003ebugcrowd-pam-###\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAfter creating the application, go to assignments and assign yourself to the application\u003c/li\u003e\n\u003cli\u003eThe Okta Privileged Access chiclet should appear on your Enduser Dashboard. Click the application and you\u0026#39;ll be redirected\u003c/li\u003e\n\u003cli\u003eFor full functionality, go to Groups, create group, and assign all team roles and assign a user to the group\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eDocumentation\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eOverview: \u003ca href=\"https://help.okta.com/en-us/content/topics/privileged-access/pam-overview.htm\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://help.okta.com/en-us/content/topics/privileged-access/pam-overview.htm\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSet up Okta Privileged Access: \u003ca href=\"https://help.okta.com/en-us/content/topics/privileged-access/pam-overview.htm\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://help.okta.com/en-us/content/topics/privileged-access/pam-setup.htm\n\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":7000,"max":35000},"2":{"min":3000,"max":7000},"3":{"min":1000,"max":3000},"4":{"min":100,"max":1000},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"731cf922-7c3a-4729-a546-aa007b4b0e47","name":"Okta Workflows","targets":[{"id":"7cbca9f8-30fa-46a4-9b87-ab7cd98465be","uri":"","name":"https://bugcrowd-pam-###.workflows.oktapreview.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4f27177b-20a3-40ff-b6a5-c59b35f345c1","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"7cbca9f8-30fa-46a4-9b87-ab7cd98465be"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7cbca9f8-30fa-46a4-9b87-ab7cd98465be"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":{"id":"004c2c52-e6bc-45f6-860c-0352dc584e03","p1MaxCents":3500000,"p1MinCents":700000,"p2MaxCents":700000,"p2MinCents":300000,"p3MaxCents":300000,"p3MinCents":100000,"p4MaxCents":100000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch4\u003eRedeem Credentials\u003c/h4\u003e\n\n\u003cp\u003eAt the bottom of the program brief, click on \u0026quot;Get Credentials\u0026quot; to retrieve 2 sets of credentials.\u003c/p\u003e\n\n\u003ch4\u003eAccess\u003c/h4\u003e\n\n\u003cp\u003eTo access Okta Workflows, go to the Okta Admin Dashboard -\u0026gt; Workflow -\u0026gt; Workflows Console\u003c/p\u003e\n\n\u003ch4\u003eFocus Areas\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eFocus Areas for Okta Workflows\u003c/li\u003e\n\u003cli\u003eAbility to perform SSRF with Flo cards\u003c/li\u003e\n\u003cli\u003eAbility to provision and deprovision Workflow orgs\u003c/li\u003e\n\u003cli\u003ePerforming Flo actions across orgs\u003c/li\u003e\n\u003cli\u003eViewing sensitive information across orgs\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eOut of Scope\u003c/h4\u003e\n\n\u003cp\u003eTesting for Denial of Service issues and testing with any sort of automation is STRICTLY out of scope. This will result in an immediate removal from Okta Workflows and in some cases, the Okta bug bounty program.\u003c/p\u003e","rewardRangeData":{"1":{"min":7000,"max":35000},"2":{"min":3000,"max":7000},"3":{"min":1000,"max":3000},"4":{"min":100,"max":1000},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"9dc43177-4490-4989-8cbb-c659c341da70","name":"Okta Device Access","targets":[{"id":"7745e718-070b-4f46-b5ed-0653e712fe8d","uri":"","name":"Desktop MFA for Windows","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"03483e5d-1b1e-4440-ad2f-386499d6559e","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"7855977b-6b8c-420c-b2ab-0f59a0554b20","uri":"","name":"Desktop MFA for macOS","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"29f9d98e-1f7c-4be1-8489-da8c267fc78d","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"12b5b994-b959-4b15-b4f9-12b4acc3c731","uri":"","name":"Password Sync for macOS","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"29b9bde7-d7bf-4ff9-a150-40356a0a6f47","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":3,"description":null,"rewardRange":{"id":"993dd64c-7525-4733-9466-6dea991c27c8","p1MaxCents":7500000,"p1MinCents":1000000,"p2MaxCents":1000000,"p2MinCents":400000,"p3MaxCents":400000,"p3MinCents":100000,"p4MaxCents":100000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch4\u003eRedeem Credentials\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eAt the bottom of the program brief, click on \u0026quot;Get Credentials\u0026quot; to retrieve 2 sets of credentials.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eOkta Device Access extends IAM (Identity and Access Management) capabilities across devices and applications, increasing your org\u0026#39;s security posture and protecting you from phishing attacks. Local device data is protected by the same Identity Provider that protects access to data and applications in the cloud.\u003c/p\u003e\n\n\u003ch4\u003eDocumentation\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://help.okta.com/oie/en-us/content/topics/oda/oda-overview.htm\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eOkta Device Access Documentation\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://help.okta.com/oie/en-us/content/topics/oda/windows-mfa/win-mfa.htm\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eDesktop MFA for Windows\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://help.okta.com/oie/en-us/content/topics/oda/macos-mfa/macos-mfa.htm\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eDesktop MFA for macOS\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://help.okta.com/oie/en-us/content/topics/oda/macos-pw-sync/macos-pw-sync.htm\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eDesktop Password Sync for macOS\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eDownloads\u003c/h4\u003e\n\n\u003cp\u003eDownload Okta Verify for Windows \u0026amp; macOS\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDesktop MFA is part of Okta Device Access, which uses Okta Verify for device registration and user authentication. In the Admin Console, go to Settings -\u0026gt; Downloads and download either \u003cstrong\u003eOkta Verify for Windows (.exe)\u003c/strong\u003e or \u003cstrong\u003eOkta Verify for macOS\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":10000,"max":75000},"2":{"min":4000,"max":10000},"3":{"min":1000,"max":4000},"4":{"min":100,"max":1000},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"ce370742-6d42-4438-a8b9-8840e548db39","name":"Okta Support Portal (support.okta.com)","targets":[{"id":"eeb87621-9250-459f-9174-97d44e841e89","uri":"https://support.okta.com","name":"support.okta.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ab08f23d-18c7-49b6-aa9c-06705b0201c4","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":4,"description":null,"rewardRange":{"id":"035e4c69-d065-49d0-84c7-558deead560a","p1MaxCents":1500000,"p1MinCents":500000,"p2MaxCents":500000,"p2MinCents":200000,"p3MaxCents":200000,"p3MinCents":50000,"p4MaxCents":50000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch4\u003eFocus Areas\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eCrafting an aura payload to view data such as first/last name, company name, and IDs will not be accepted. If you are able to view credentials, emails, phone numbers, etc. these will be reviewed and accepted at the sole discretion of Okta.\u003c/li\u003e\n\u003cli\u003eTampering, manipulating, or deleting customer data is strictly out of scope and these tests should be conducted against your own test account.\u003c/li\u003e\n\u003cli\u003eEligible reports will be awarded based on severity, to be determined by Okta in its sole discretion.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":5000,"max":15000},"2":{"min":2000,"max":5000},"3":{"min":500,"max":2000},"4":{"min":100,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"5e76f0ba-4d58-4189-b5c1-fe42023f842a","name":"AtSpoke (Okta Access Requests) (New)","targets":[{"id":"012a7213-b094-42b2-a6bf-dd062138fba8","uri":"","name":"https://bugcrowd-pam-###.at.oktapreview.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d58ec6e1-d233-4786-90e6-ff5366e7318c","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"012a7213-b094-42b2-a6bf-dd062138fba8"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"012a7213-b094-42b2-a6bf-dd062138fba8"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":5,"description":null,"rewardRange":{"id":"d60808ea-4963-4689-8a8e-b046b109957b","p1MaxCents":2500000,"p1MinCents":500000,"p2MaxCents":500000,"p2MinCents":200000,"p3MaxCents":200000,"p3MinCents":50000,"p4MaxCents":50000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eOkta Access Request is enabled for all OIE orgs\u003c/p\u003e","rewardRangeData":{"1":{"min":5000,"max":25000},"2":{"min":2000,"max":5000},"3":{"min":500,"max":2000},"4":{"min":100,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"90b77d2d-d460-4b98-a259-f9ffa94bdd00","name":"Okta (OIE) In-Scope Targets (New)","targets":[{"id":"50e5b7cb-7e83-4e77-bbcc-3a9fd6f467fd","uri":"","name":"https://bugcrowd-pam-###.oktapreview.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"904b43d0-11af-4b75-ac11-5a09ce74a4f8","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"50e5b7cb-7e83-4e77-bbcc-3a9fd6f467fd"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"50e5b7cb-7e83-4e77-bbcc-3a9fd6f467fd"}],"recentChangeFlags":null},{"id":"f4a2c06f-1cc5-4a03-a8a2-a503bc093651","uri":"https://www.okta.com/fastpass/","name":"Okta Verify Fastpass","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"012c63a9-1173-4fe4-87d5-ac10f994c63a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"7b384f16-6167-423b-a058-de1aa19f61d6","uri":"","name":"https://bugcrowd-pam-###-admin.oktapreview.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ead895ef-748e-47b6-a8a8-e572ba5cb970","sortOrder":2},"sortOrder":2,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"7b384f16-6167-423b-a058-de1aa19f61d6"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7b384f16-6167-423b-a058-de1aa19f61d6"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":6,"description":null,"rewardRange":{"id":"993dd64c-7525-4733-9466-6dea991c27c8","p1MaxCents":7500000,"p1MinCents":1000000,"p2MaxCents":1000000,"p2MinCents":400000,"p3MaxCents":400000,"p3MinCents":100000,"p4MaxCents":100000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch3\u003eRedeem Credentials\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAt the bottom of the program brief, click on \u0026quot;Get Credentials\u0026quot; to retrieve 2 sets of credentials.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eDO THIS FIRST!\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eChange the email address associated with the provided users so that you can handle your own password resets\u003c/li\u003e\n\u003cli\u003eCreate at least 2 other Super Admins in each ORG for resetting locked accounts and handling account problems.\u003c/li\u003e\n\u003cli\u003eFollow the steps to setup and enforce MFA on each Login under \u0026quot;Required MFA Configuration\u0026quot;\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":10000,"max":75000},"2":{"min":4000,"max":10000},"3":{"min":1000,"max":4000},"4":{"min":100,"max":1000},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"a4210bf9-ebb3-44d4-9a60-837aa79951e3","name":"Okta (Classic) In-Scope Targets","targets":[{"id":"cb1418c9-1af0-4035-8cfa-afb43982db32","uri":null,"name":"bugcrowd-%username%-1.oktapreview.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"669cb515-8cec-4f06-a991-a643b026f253","sortOrder":0},"sortOrder":0,"tags":[{"id":"4592d652-bb2d-4ab9-8720-08fe80de0dc4","name":"Backbone","targetId":"cb1418c9-1af0-4035-8cfa-afb43982db32"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"cb1418c9-1af0-4035-8cfa-afb43982db32"}],"recentChangeFlags":null},{"id":"189d4a91-9bfd-4085-8447-93da0898b745","uri":null,"name":"bugcrowd-%username%-2.oktapreview.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"161275c1-af9d-4b89-bfe5-8231a8493e7f","sortOrder":0},"sortOrder":0,"tags":[{"id":"4592d652-bb2d-4ab9-8720-08fe80de0dc4","name":"Backbone","targetId":"189d4a91-9bfd-4085-8447-93da0898b745"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"189d4a91-9bfd-4085-8447-93da0898b745"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":7,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eAs of May 15th 2024, Okta Classic is out of scope. Please refer to Okta OIE.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"fe6656c8-726c-46e7-93bd-44692c0a72a6","name":"Advanced Server Access","targets":[{"id":"32e4dfc7-0ce2-491e-8c7d-4d8fd937d323","uri":"https://www.okta.com/products/advanced-server-access/","name":"Advanced Server Access (ASA) / (ScaleFT)","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4658f0da-b4bf-440a-831e-1c1f5f88250e","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"0ede2aa0-54fc-44c3-b80c-d3e677ad1233","uri":"","name":"http://app.scaleft.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9449c754-af7e-4b5e-b69e-86af89c17785","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"df99cf13-b0ab-49ad-aa1c-8c734ca12020","uri":"https://help.okta.com/asa/en-us/Content/Topics/Adv_Server_Access/docs/client.htm","name":"Advanced Server Access Client / Agents","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e6b8b4b3-b65c-4651-83c5-a7ece06f6c82","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":8,"description":null,"rewardRange":{"id":"004c2c52-e6bc-45f6-860c-0352dc584e03","p1MaxCents":3500000,"p1MinCents":700000,"p2MaxCents":700000,"p2MinCents":300000,"p3MaxCents":300000,"p3MinCents":100000,"p4MaxCents":100000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch3\u003eAccount Creation for Advanced Server Access\u003c/h3\u003e\n\n\u003ch4\u003eSteps\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eIn order to participate in Okta\u0026#39;s bug bounty program you are required to have a \u003ca href=\"https://bugcrowd.com/user/sign_up\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd account\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eVisit \u003ca href=\"https://app.scaleft.com/p/signupV2\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAdvanced Server Access\u003c/a\u003e and create your account using the naming convention \u003ccode\u003ebugcrowd-\u0026lt;username\u0026gt;\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003e!!NOTE!!\u003c/strong\u003e Please sign up for an account using your @bugcrowdninja.com email addres. Once again, ALL organization/team names must follow the naming convention \u003ccode\u003ebugcrowd-\u0026lt;username\u0026gt;\u003c/code\u003e.\u003c/p\u003e\n\n\u003cp\u003eFor more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. Researchers will not be asked for credit card information and will not be billed.\u003c/p\u003e","rewardRangeData":{"1":{"min":7000,"max":35000},"2":{"min":3000,"max":7000},"3":{"min":1000,"max":3000},"4":{"min":100,"max":1000},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"35466ce7-70e5-47f2-976a-a9b09fe5b306","name":"Other In-Scope Targets","targets":[{"id":"239aaee4-54bd-4b4c-b5e3-d6fe71b9e203","uri":"https://apps.apple.com/us/app/okta-verify/id490179405","name":"Okta Verify (iOS)","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6ef6f5fe-cf1d-4b64-b142-7b62382297a6","sortOrder":0},"sortOrder":0,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"239aaee4-54bd-4b4c-b5e3-d6fe71b9e203"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"239aaee4-54bd-4b4c-b5e3-d6fe71b9e203"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"239aaee4-54bd-4b4c-b5e3-d6fe71b9e203"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"239aaee4-54bd-4b4c-b5e3-d6fe71b9e203"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"239aaee4-54bd-4b4c-b5e3-d6fe71b9e203"}],"recentChangeFlags":null},{"id":"7bee58f0-28ab-486b-b0ff-54260656a9f3","uri":"https://play.google.com/store/apps/details?id=com.okta.android.auth\u0026hl=en_US\u0026gl=US","name":"Okta Verify (Android)","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"8fe38802-f923-42d0-b58c-89b04ffd4049","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"7bee58f0-28ab-486b-b0ff-54260656a9f3"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"7bee58f0-28ab-486b-b0ff-54260656a9f3"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"7bee58f0-28ab-486b-b0ff-54260656a9f3"}],"recentChangeFlags":null},{"id":"3c0e299c-5b58-4857-aafa-cd6bc22a90cc","uri":"https://apps.apple.com/us/app/okta-verify/id490179405","name":"Okta Verify (Mac OS)","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"77d9ef37-637d-43dd-b797-890ad8872426","sortOrder":0},"sortOrder":0,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"3c0e299c-5b58-4857-aafa-cd6bc22a90cc"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"3c0e299c-5b58-4857-aafa-cd6bc22a90cc"},{"id":"c5df6ad0-33b4-40ac-b6dd-8d4038997d40","name":"macOS","targetId":"3c0e299c-5b58-4857-aafa-cd6bc22a90cc"}],"recentChangeFlags":null},{"id":"f770eedd-51e3-461a-9c09-337b0da63983","uri":"","name":"Okta Verify (Windows)","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c495cb4e-6413-4c2d-bb7f-d0386daff7dd","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"c9db0e76-80dd-4a56-94cf-13b917b5b846","uri":"","name":"Okta On-Prem Agents ( AD, LDAP, RDP, IWA )","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f168d485-3466-43a6-b4fb-9dff56cb42cc","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"c9db0e76-80dd-4a56-94cf-13b917b5b846"},{"id":"70f8fc74-f147-45d5-8f56-9bff2f555bd7","name":".NET","targetId":"c9db0e76-80dd-4a56-94cf-13b917b5b846"}],"recentChangeFlags":null},{"id":"ae530490-25fa-4b51-b14e-f56ad3e31e3a","uri":"https://help.okta.com/en/prod/Content/Topics/Adv_Server_Access/docs/sftd-windows.htm","name":"Okta Agent Windows","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a211d609-d022-421b-94f9-6ff40dca710a","sortOrder":0},"sortOrder":0,"tags":[{"id":"9c63a0f4-0db6-40da-85f0-65d0aa72bfbe","name":"Windows","targetId":"ae530490-25fa-4b51-b14e-f56ad3e31e3a"}],"recentChangeFlags":null},{"id":"1e535716-6f02-4143-b3ff-32687646193e","uri":"https://help.okta.com/en/prod/Content/Topics/Settings/download-browser-plugin.htm","name":"Okta Browser Plugin (IE / Firefox / Chrome)","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7e1ab350-096b-401b-8ef1-3ae17f109b6c","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":9,"description":null,"rewardRange":{"id":"993dd64c-7525-4733-9466-6dea991c27c8","p1MaxCents":7500000,"p1MinCents":1000000,"p2MaxCents":1000000,"p2MinCents":400000,"p3MaxCents":400000,"p3MinCents":100000,"p4MaxCents":100000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":10000,"max":75000},"2":{"min":4000,"max":10000},"3":{"min":1000,"max":4000},"4":{"min":100,"max":1000},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"bc91b26c-04a7-44cb-863b-4737ba137d61","name":"Out of Scope Targets","targets":[{"id":"11e4635d-c2ea-4387-9107-8f2fa07272f9","uri":"","name":"*.okta.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e9d671cc-1679-4b6d-8171-038adc5010c7","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"ac5b53c6-a3f6-4f64-b059-e1fdc8074470","uri":"","name":"*.trexcloud.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b33f1a24-43e2-4e37-b3ae-c93efb39a032","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"5667a223-8d8b-46ee-85e3-40beece89d01","uri":"","name":"login.okta.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"9343d7ed-2eb9-4f25-b925-ac0f3544c2d0","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"2005a229-73ed-47f9-8179-9f6d1974f785","uri":"","name":"pages.okta.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"80b79373-ad05-4c6a-88f4-57c2df04e543","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"4b6dceac-8846-4be0-95f0-1e8d83acfb09","uri":"","name":"developer.okta.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ba3dec0f-e19d-4d7d-9cb9-87350448e4b5","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"53a8f897-7542-4cd5-8d87-ee76972fbaa1","uri":"","name":"trust.okta.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4572178b-3399-48f2-b5fc-510e6f79d841","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"9ca6fde1-94d3-48c3-b773-715c0d4c4696","uri":"","name":"www.okta.com (static site)","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"0f856115-773e-48df-a39e-23224c3c61de","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"d619aac0-9e21-46aa-af93-3a3879365cdb","uri":"","name":"https://scaleft.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2782d108-3bfa-43b6-9891-b377b9459576","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"e482d162-b060-4bd7-a459-6e0b973b0d32","uri":"","name":"https://app.scaleft.com/p/signup","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7ae4a743-96a6-4534-9b82-6805f3a428c0","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"a3da811d-d31f-42ad-ba2e-a0668d947e06","uri":"https://github.com/oktadev","name":"https://github.com/oktadev","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"688c4820-dac7-46f1-8489-8981b36794c4","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"a2898673-c048-4648-b2c8-722cfbeecd2a","uri":"","name":"Backend Okta non-app infrastructure","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"1292a191-cd3b-4ec1-ae80-ca64721e2a47","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"7057804e-4885-444e-92a0-29f6b2c4e5b6","uri":"","name":"Network layer issues","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d35cb435-cc18-4c28-965a-f81277517151","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"b211e37a-8147-46bb-acaf-630a471a9cbe","uri":"","name":"AtSpoke - Okta Workflows actions in access requests","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4183bf25-617e-43af-82d2-7e7f6dd7c7e7","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"389c2243-f029-4f16-861d-c2adc2b1268e","uri":"","name":"AtSpoke - Entitlement bundles as a resource in access requests","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b8311836-3bc8-4507-ac3d-976e31454e63","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"4de83f99-1571-4d87-8fa2-0aad2935e495","uri":"","name":"Anything not explicitly called out above as in-scope","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"565b4257-bbb1-475a-8733-936bf3150d6d","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":10,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"f2f9e672-46c8-4d45-8dd0-ec606fcd1ca4","code":"okta","state":"in_progress","endsAt":null,"bountyId":"1a57d8fd-6de3-489c-b198-ccd69a3e0a2b","startsAt":"2016-11-16T14:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Cloud","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/ec9b/bc74/f5d2add7/d20c4783e3e1bb9f3d6ec15c4bfeb108_Okta_Aura_CMYK_Black.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2016-11-16T14:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/okta","changelogs":"/engagements/okta/changelog","submissions":null,"announcements":"/engagements/okta/announcements","hallOfFame":"/engagements/okta/hall_of_fames","crowdstream":"/engagements/okta/crowdstream"},"announcementsCount":31,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/okta/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=okta\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/okta/engagement_subscribers","engagementChangelogsUrl":"/engagements/okta/changelog","publishedAt":"2026-05-22T16:13:07.121Z","engagementChangelogUrl":"/engagements/okta/changelog/d4dc2398-db8d-4b89-9f7f-0aae75251307","createUserFeedbacksUrl":"/engagements/okta/feedbacks","engagementCrowdstreamUrl":"/engagements/okta/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}