{"id":"2ed64b94-6bb3-4d9b-b03b-af5d0d091095","engagementId":"ec5808ec-6b39-437c-a3ca-a93dcb34a01c","data":{"brief":{"id":"d8242a7d-1c75-4d18-b9c2-41626a2c609f","name":"Office of Personnel Management - Vulnerability Disclosure Program","tagline":"Submit your findings!","description":"\u003cp\u003eAs part of a U.S. government agency, the Office of Personnel Management (OPM) takes seriously our responsibility to protect the public's information, including financial and personal information, from unwarranted disclosure.\u003c/p\u003e\n\n\u003cp\u003eWe want security researchers to feel comfortable reporting any vulnerabilities they discover, as set out in this policy, so that we can fix them and keep our information safe.\u003c/p\u003e\n\n\u003cp\u003eThis policy describes what systems and types of research are covered under this policy, how to send us vulnerability reports, and how long we ask security researchers to wait before publicly disclosing any vulnerabilities.\u003c/p\u003e\n\n\u003cp\u003eOPM encourages you to contact us to report potential vulnerabilities in our systems.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"2a38890b-c88e-4bc0-8db0-02059f3fafe6","targetsOverview":"\u003ch2\u003eAuthorization\u003c/h2\u003e\n\n\u003cp\u003eIf you make a good faith effort to comply with this policy during your security research, OPM will consider your research to be authorized. OPM will not pursue legal action against authorized research.\u003c/p\u003e\n\n\u003ch2\u003eGuidelines\u003c/h2\u003e\n\n\u003cp\u003eWe require that you:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNotify us as soon as possible after you discover a real or potential security issue.\u003c/li\u003e\n\u003cli\u003eMake every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.\u003c/li\u003e\n\u003cli\u003eOnly use exploits to the extent necessary to confirm a vulnerability. Do not use an exploit to compromise or exfiltrate data, establish command line access and/or persistence, or use the exploit to \"pivot\" to other systems.\u003c/li\u003e\n\u003cli\u003eOnce you have established that a vulnerability exists, or encountered any of the sensitive data (including personally identifiable information, financial information, or proprietary information or trade secrets of any party), you must stop your test and notify us immediately, and not disclose this information to anyone else.\u003c/li\u003e\n\u003cli\u003eProvide us a reasonable amount of time to resolve the issue before you disclose it publicly.\u003c/li\u003e\n\u003cli\u003eKeep confidential any information about discovered vulnerabilities for up to 90 calendar days after you have notified OPM.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eScope\u003c/h2\u003e\n\n\u003cp\u003eThis policy applies to the following domains:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eExternal facing OPM registered and managed .gov domains and all sub-domains (e.g. telework.opm.gov)\u003c/li\u003e\n\u003cli\u003eapplicationmanager.gov\u003c/li\u003e\n\u003cli\u003echcoc.gov\u003c/li\u003e\n\u003cli\u003ecybercareers.gov\u003c/li\u003e\n\u003cli\u003eemployeeexpress.gov\u003c/li\u003e\n\u003cli\u003efeb.gov\u003c/li\u003e\n\u003cli\u003efederaljobs.gov\u003c/li\u003e\n\u003cli\u003efedjobs.gov\u003c/li\u003e\n\u003cli\u003efedshirevets.gov\u003c/li\u003e\n\u003cli\u003efsafeds.gov\u003c/li\u003e\n\u003cli\u003egolearn.gov\u003c/li\u003e\n\u003cli\u003egovernmentjobs.gov\u003c/li\u003e\n\u003cli\u003eopm.gov\u003c/li\u003e\n\u003cli\u003epac.gov\u003c/li\u003e\n\u003cli\u003epmf.gov\u003c/li\u003e\n\u003cli\u003etelework.gov\u003c/li\u003e\n\u003cli\u003eunlocktalent.gov\u003c/li\u003e\n\u003cli\u003eusajobs.gov\u003c/li\u003e\n\u003cli\u003eusalearning.gov\u003c/li\u003e\n\u003cli\u003eusastaffing.gov\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eNon-public data on public third-party services\u003c/h2\u003e\n\n\u003cp\u003eOPM utilizes third-party services to support its public work model. While non-public data published publicly on those services is in scope, testing those services is not in scope.\u003c/p\u003e\n\n\u003cp\u003eAny services not expressly listed above, such as any connected services, are excluded from scope and are not authorized for testing. Additionally, vulnerabilities found in non-federal systems from our vendors fall outside of this policy's scope and should be reported directly to the vendor according to their disclosure policy (if any). If you are not sure whether a system or endpoint is in scope or not, contact us at \u003ca href=\"mailto:support@bugcrowd.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esupport@bugcrowd.com\u003c/a\u003e before starting your research.\u003c/p\u003e\n\n\u003cp\u003eOPM does not offer any compensation for the identification or reporting of vulnerabilities.\u003c/p\u003e\n\n\u003ch2\u003eTest methods\u003c/h2\u003e\n\n\u003cp\u003eSecurity Researchers/Testers must not:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePerform testing of any information system or service unless it is in the Scope of this policy\u003c/li\u003e\n\u003cli\u003ePerform any Denial of Service (DoS or DDoS), Resource Exhaustion, or other tests that impair access to an information system or data (information)\u003c/li\u003e\n\u003cli\u003ePerform physical testing ( e.g. office access, open doors, tailgating) of federal/contractor facilities or resources\u003c/li\u003e\n\u003cli\u003ePerform social engineering ( e.g. phishing, vishing), or any other non-technical vulnerability testing to include the sending of unsolicited emails\u003c/li\u003e\n\u003cli\u003eIntroduce any malicious software/code\u003c/li\u003e\n\u003cli\u003ePerform testing in a manner which could degrade the operations of systems, or intentionally impair, disrupt, or disable information systems or services\u003c/li\u003e\n\u003cli\u003ePerform testing on third-party applications, websites, or services that integrate with or link to or from agency information systems or services\u003c/li\u003e\n\u003cli\u003ePerform testing that intentionally or unintentionally deletes, alters, shares, retains, or destroys information (data)\u003c/li\u003e\n\u003cli\u003ePerform testing of an exploit to exfiltrate data, establish command line access, elevate privileges, establish a persistent presence on systems, or \"pivot\" to other systems\u003c/li\u003e\n\u003cli\u003ePerform testing that maintains a persistent presence on information systems or services\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSecurity Researchers/Testers must:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eCease testing and notify us immediately upon discovery of a vulnerability\u003c/li\u003e\n\u003cli\u003eCease testing and notify us immediately upon discovery of an exposure of nonpublic data to include Personally Identifiable Information (PII), Financial information ( e.g. credit card or bank account numbers), and Proprietary information or trade secrets of companies of any party\u003c/li\u003e\n\u003cli\u003ePurge any stored agency nonpublic data upon reporting a vulnerability\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eReporting a Vulnerability\u003c/h2\u003e\n\n\u003cp\u003eWe accept vulnerability reports using the provided reporting format via the following methods:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eEmail: All submissions via email will be sent to \u003ca href=\"mailto:opm-vdp@submit.bugcrowd.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eopm-vdp@submit.bugcrowd.com\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThe Vulnerability Report should be in the template provided. Vulnerability Reports that are not in the correct template or that do not provide sufficient information will be rejected for processing by the analysis team.\u003c/p\u003e\n\n\u003cp\u003ePlease note that Vulnerability Reports may be submitted anonymously. If you share contact information (Reporter Contact), we will acknowledge receipt of your report within five (5) business days of the report's receipt.\u003c/p\u003e\n\n\u003cp\u003eWe do not support PGP-encrypted emails. For particularly sensitive information, submit through the mail process or provide a note that some information is sensitive, and you will be contacted with details on sending the sensitive information.\u003c/p\u003e\n\n\u003ch2\u003eWhat we would like to see from you:\u003c/h2\u003e\n\n\u003cp\u003eIn order to help us triage and prioritize submissions, we recommend that your reports:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDescribe the location the vulnerability was discovered and the potential impact of exploitation.\u003c/li\u003e\n\u003cli\u003eOffer a detailed description of the steps needed to reproduce the vulnerability (proof of concept scripts or screenshots are helpful).\u003c/li\u003e\n\u003cli\u003eBe in English, if possible.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eWhat you can expect from us:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen you choose to share your contact information with us, we commit to coordinating with you as openly and as quickly as possible.\u003c/li\u003e\n\u003cli\u003eWithin three (3) business days, we will acknowledge that your report has been received.\u003c/li\u003e\n\u003cli\u003eTo the best of our ability, we will confirm the existence of the vulnerability to you and be as transparent as possible about what steps we are taking during the remediation process, including on issues or challenges that may delay resolution.\nWe will maintain an open dialogue to discuss issues.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eThe Cybersecurity and Infrastructure Security Agency (CISA) Vulnerability Disclosure Policy Platform (VDP Platform) gives agencies the option to use a centrally managed system to intake vulnerability information from and collaborate with the public to improve the security of their internet-accessible systems. CISA has a contract with EnDyna and Bugcrowd, private companies, to manage the platform used by the public to report vulnerability information; CISA exercises general oversight of the program.  CISA does not collect, maintain, use, or disseminate any Personally Identifiable Information (PII) provided to Bugcrowd for the purposes of creating a profile on the website or reporting a vulnerability to agencies other than CISA.  Participating agencies provide their own program vulnerability disclosure policy, setting out the agency’s parameters for vulnerability disclosures, including provisions for collection and use of submitted information. Any submissions of vulnerabilities pertaining to CISA’s own information systems would be governed by the DHS VDP brief.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[],"resources":[],"engagement":{"id":"ec5808ec-6b39-437c-a3ca-a93dcb34a01c","code":"opm-vdp","state":"in_progress","endsAt":null,"bountyId":"ee515567-cc45-4dea-9378-3569e7847acd","startsAt":"2022-06-21T16:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Government","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/145c/307e/0cd4a22b/c7f490c986c63c9c9124af210ea92439_opm.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2022-06-21T16:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/opm-vdp","changelogs":"/engagements/opm-vdp/changelog","submissions":null,"announcements":"/engagements/opm-vdp/announcements","hallOfFame":"/engagements/opm-vdp/hall_of_fames","crowdstream":"/engagements/opm-vdp/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/opm-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=opm-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/opm-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/opm-vdp/changelog","publishedAt":"2022-06-10T18:24:39.348Z","engagementChangelogUrl":"/engagements/opm-vdp/changelog/2ed64b94-6bb3-4d9b-b03b-af5d0d091095","createUserFeedbacksUrl":"/engagements/opm-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/opm-vdp/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}