{"id":"ff365908-5159-4d8d-9895-43512891a90b","engagementId":"190bdc65-fbd8-4587-a4c7-215325f87cef","data":{"brief":{"id":"7ab17b63-7295-46a1-b3db-786ec22dffca","name":"Opsgenie","tagline":"Opsgenie is a modern incident management platform for operating always-on services, empowering Dev \u0026 Ops teams to plan for service disruptions and stay in control during incidents.","description":"\u003cp\u003eOpsgenie is a modern incident management platform for operating always-on services, empowering Dev \u0026amp; Ops teams to plan for service disruptions and stay in control during incidents. With over 200 deep integrations and a highly flexible rules engine, Opsgenie centralizes alerts, notifies the right people reliably, and enables them to collaborate and take rapid action. Throughout the entire incident lifecycle, Opsgenie tracks all activity and provides actionable insights to improve productivity and drive continuous operational efficiencies.\u003c/p\u003e\n\n\u003ch2\u003eGet Started (tl;dr version)\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eTesting for Opsgenie is to be performed on \u003cstrong\u003ehttps://*.opsgenie.com\u003c/strong\u003e using free-trial accounts.\u003c/li\u003e\n\u003cli\u003eDo not access, impact, destroy or otherwise negatively impact Opsgenie customers, or customer data in anyway.\u003c/li\u003e\n\u003cli\u003eEnsure that you use your @bugcrowdninja.com email address.\u003c/li\u003e\n\u003cli\u003eEnsure you understand the targets, scopes, exclusions, and rules below.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eQuick Links\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eOpsgenie Links\n\n\u003cul\u003e\n\u003cli\u003eWebsite\n\n\u003cul\u003e\n\u003cli\u003e\n\u003ca href=\"https://docs.opsgenie.com/docs/welcome\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.opsgenie.com/docs/welcome\u003c/a\u003e\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.opsgenie.com/docs/opsgenie-quick-start-guide\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.opsgenie.com/docs/opsgenie-quick-start-guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.opsgenie.com/docs/new-user-guide\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.opsgenie.com/docs/new-user-guide\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eDocs\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://docs.opsgenie.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.opsgenie.com/\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFor real time support you can also use Intercom chat bubble on bottom right of www.opsgenie.com\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAPI Docs\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://docs.opsgenie.com/docs/api-overview\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.opsgenie.com/docs/api-overview\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.opsgenie.com/docs/api-access-management\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.opsgenie.com/docs/api-access-management\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.opsgenie.com/docs/authentication\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.opsgenie.com/docs/authentication\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.opsgenie.com/docs/alert-api\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.opsgenie.com/docs/alert-api\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.opsgenie.com/docs/user-api\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.opsgenie.com/docs/user-api\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eMobile apps\n\n\u003cul\u003e\n\u003cli\u003e(Android) \u003ca href=\"https://play.google.com/store/apps/details?id=com.ifountain.opsgenie\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://play.google.com/store/apps/details?id=com.ifountain.opsgenie\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e(iOS) \u003ca href=\"https://itunes.apple.com/us/app/opsgenie/id528590328\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://itunes.apple.com/us/app/opsgenie/id528590328\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthentication\u003c/li\u003e\n\u003cli\u003eSession Management\u003c/li\u003e\n\u003cli\u003eHTTP and Cookie Security\u003c/li\u003e\n\u003cli\u003eMulti Tenant Data Leakage/Access\u003c/li\u003e\n\u003cli\u003eServer-side Remote Code Execution (RCE)\u003c/li\u003e\n\u003cli\u003eServer-Side Request Forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eStored/Reflected Cross-site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eInjection\u003c/li\u003e\n\u003cli\u003eXML External Entity Attacks (XXE)\u003c/li\u003e\n\u003cli\u003eAccess Control \u0026amp; Authorization Vulnerabilities\u003c/li\u003e\n\u003cli\u003ePath/Directory Traversal Issues\u003c/li\u003e\n\u003cli\u003eFile Upload \u0026amp; File hosting\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eEnsure you review the out of scope and exclusions list for further details.\u003cbr\u003e\n** Cross Instance Data Leakage/Access refers to unauthorised data access between instances.\u003c/p\u003e\n\n\u003ch2\u003eCreating Your Instance\u003c/h2\u003e\n\n\u003cp\u003eResearchers can sign up here: https://www.atlassian.com/software/opsgenie/try\u003cbr\u003e\nNote: Remember to use your @bugcrowdninja.com email address\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e!! Do not forget to verify your account by clicking on the link via email, some features will not work until verification is complete. !!\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAdditional documents:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://docs.opsgenie.com/docs/welcome\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.opsgenie.com/docs/welcome\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.opsgenie.com/docs/opsgenie-quick-start-guide\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.opsgenie.com/docs/opsgenie-quick-start-guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.opsgenie.com/docs/quick-set-up-video\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.opsgenie.com/docs/quick-set-up-video\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.opsgenie.com/docs/new-user-guide\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.opsgenie.com/docs/new-user-guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.opsgenie.com/docs/users\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.opsgenie.com/docs/users\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eDisclosure Request Guidance\u003c/h2\u003e\n\n\u003cp\u003eSubmissions that meet the following requirements will be considered for disclosure upon request:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe submission has been accepted\u003c/li\u003e\n\u003cli\u003eThe reported vulnerability has been fixed and released in production\u003c/li\u003e\n\u003cli\u003eThe submission does not regard a customer instance or a customer’s account \u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003ch2\u003eRules, Exclusions, and Scopes\u003c/h2\u003e\n\n\u003cp\u003eAny domain/property of Opsgenie not listed in the targets section is strictly out of scope (for more detailed information please see the out of scope and exclusions sections below). Researchers should use their @bugcrowdninja.com email address when signing up for an account.\u003c/p\u003e\n\n\u003cp\u003eAll resources within your instance are in scope (see below for exclusions), this includes the REST API.\u003c/p\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cp\u003eAnything not declared as a target or in scope above should be considered out of scope for the purposes of this bug bounty. However to help avoid grey areas, below are examples of what is considered out of scope.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eBlind XSS must not return any user data that you do not have access to (e.g. Screen shots, cookies that aren't owned by you, etc); when testing for blind XSS, please use the least invasive test possible (e.g. calling 1x1 image or nonexistent page on your webserver, etc).\u003c/li\u003e\n\u003cli\u003eWhen testing, please exercise caution if injecting on any form that may be publicly visible - such as forums, etc. Before injection, please make sure your payload can be removed from the site. If it cannot be easily removed, please check with support@bugcrowd before performing the testing. \u003c/li\u003e\n\u003cli\u003eNo pivoting or post exploitation attacks (i.e. using a vulnerability to find another vulnerability) are allowed on this program. DO NOT under any circumstance leverage a finding to identify further issues.\u003c/li\u003e\n\u003cli\u003eCustomer cloud instances and data are explicitly out of scope.\u003c/li\u003e\n\u003cli\u003eAny repository that you are not an owner of - do not impact Opsgenie customers in any way.\u003c/li\u003e\n\u003cli\u003eAny Opsgenie billing system. However, specific endpoints that are used inside of a target are in scope. For example, if a REST endpoint is proven to be called from one of the targets, then that endpoint is considered to be in scope. However, all other endpoints are not considered to be in scope, as they are not called from the instance at any stage.\u003c/li\u003e\n\u003cli\u003eAny internal or development services\u003c/li\u003e\n\u003cli\u003eThird party add-ons/integrations others than those listed in the targets from the marketplace are strictly excluded (vulnerabilities that exist within third-party apps in any way) - we will pass on any vulnerabilities found, however, they will not be eligible for a bounty.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eThe following finding types are specifically excluded from the bounty\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe use of Automated scanners is strictly prohibited (we have these tools too - don't even think about using them)\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g. Stack Traces, application or server errors).\u003c/li\u003e\n\u003cli\u003eFingerprinting / banner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eDisclosure of known public files or directories, (e.g. robots.txt).\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eCSRF attacks that require knowledge of the CSRF token (e.g. attacks involving a local machine).\u003c/li\u003e\n\u003cli\u003eLogout Cross-Site Request Forgery (logout CSRF).\u003c/li\u003e\n\u003cli\u003eContent Spoofing.\u003c/li\u003e\n\u003cli\u003ePresence of application or web browser ‘autocomplete’ or ‘save password’ functionality.\u003c/li\u003e\n\u003cli\u003eLack of Secure/HTTPOnly flags on non-sensitive Cookies.\u003c/li\u003e\n\u003cli\u003eLack of Security Speedbump when leaving the site.\u003c/li\u003e\n\u003cli\u003eWeak Captcha / Captcha Bypass.\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force and account lockout not enforced.\u003c/li\u003e\n\u003cli\u003eOPTIONS HTTP method enabled.\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration.\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers, specifically (https://www.owasp.org/index.php/List_of_useful_HTTP_headers), e.g.\n\n\u003cul\u003e\n\u003cli\u003eStrict-Transport-Security.\u003c/li\u003e\n\u003cli\u003eX-Frame-Options.\u003c/li\u003e\n\u003cli\u003eX-XSS-Protection.\u003c/li\u003e\n\u003cli\u003eX-Content-Type-Options.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy, X-Content-Security-Policy, X-WebKit-CSP.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy-Report-Only.\u003c/li\u003e\n\u003cli\u003eCache-Control and Pragma\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eHTTP/DNS cache poisoning.\u003c/li\u003e\n\u003cli\u003eSSL/TLS Issues, e.g.\n\n\u003cul\u003e\n\u003cli\u003eSSL Attacks such as BEAST, BREACH, Renegotiation attack.\u003c/li\u003e\n\u003cli\u003eSSL Forward secrecy not enabled.\u003c/li\u003e\n\u003cli\u003eSSL weak/insecure cipher suites.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eNo Load testing (DoS/DDoS etc) is allowed on the instance.\n\n\u003cul\u003e\n\u003cli\u003eThis includes application DoS as well as network DoS.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSelf-XSS reports will not be accepted.\n\n\u003cul\u003e\n\u003cli\u003eSimilarly, any XSS where local access is required (i.e. User-Agent Header injection) will not be accepted. The only exception will be if you can show a working off-path MiTM attack that will allow for the XSS to trigger.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerabilities that are limited to outdated browsers will not be accepted (i.e. \"this exploit only works in IE6/IE7\"). Ensure you're testing on the latest versions of your browser.\u003c/li\u003e\n\u003cli\u003eKnown vulnerabilities in used libraries, or the reports that Opsgenie uses an outdated third party library (e.g. jQuery, Apache HttpComponents etc) unless you can prove exploitability.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect SPF records of any kind. This includes DMARC.\u003c/li\u003e\n\u003cli\u003eSource code disclosure vulnerabilities.\u003c/li\u003e\n\u003cli\u003eInformation disclosure of non-confidential information (e. g. issue id, project id, commit hashes).\u003c/li\u003e\n\u003cli\u003eThe ability to upload/download viruses or malicious files to the platform.\u003c/li\u003e\n\u003cli\u003eEmail bombing\u003c/li\u003e\n\u003cli\u003eFlooding\u003c/li\u003e\n\u003cli\u003eLack of rate limiting\u003c/li\u003e\n\u003cli\u003eCSV Injection\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou must ensure that customer data is not affected in any way as a result of your testing. Please ensure you're being non-destructive whilst testing and are only testing on instances that you own.\u003c/li\u003e\n\u003cli\u003eIn addition to above, customer instances are not to be accessed in any way (i.e. no customer data is accessed, customer credentials are not to be used or \"verified\")\n\n\u003cul\u003e\n\u003cli\u003eIf you believe you have found sensitive customer data (e.g., login credentials, API keys etc) or a way to access customer data (i.e. through a vulnerability) report it, but do not attempt to successfully validate if/that it works.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cem\u003eUse of any automated tools/scanners is strictly prohibited\u003c/em\u003e and will lead to you being removed from the program (trust us, we have those tools too).\u003c/li\u003e\n\u003cli\u003eReports need to be submitted in plain text (associated pictures/videos are fine as long as they're in standard formats). Non-plain text reports (e.g. PDF, DOCX) will be asked to be resubmitted in plain text.\u003c/li\u003e\n\u003cli\u003eSufficiently similar access control issues should be grouped in one report. Atlassian defines “sufficiently similar” as issues that use the same configuration for bypassing a particular control, which may be used on multiple related vulnerable endpoints or actions (User X can Create/Delete/Edit Resource Y).\u003c/li\u003e\n\u003cli\u003eGrants/awards are at the discretion of Atlassian and we withhold the right to grant, modify or deny grants. But we'll be fair about it.\u003c/li\u003e\n\u003cli\u003eTax implications of any payouts are the sole responsibility of the reporter.\u003c/li\u003e\n\u003cli\u003eDo NOT conduct non-technical attacks such as social engineering, phishing or unauthorized access to infrastructure.\u003c/li\u003e\n\u003cli\u003eDo NOT test the physical security of Opsgenie offices, employees, equipment, etc.\u003c/li\u003e\n\u003cli\u003eThis bounty follows Bugcrowd’s standard disclosure terms.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eReporting Guidelines\u003c/h3\u003e\n\n\u003cp\u003eWhere applicable, please include the following information. This will greatly assist in the triage, validation, and acceptance processes and will result in more clear security risk communication and timely report acceptances.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eBrief summary (please include product versions affected/tested)\u003c/li\u003e\n\u003cli\u003ePrerequisites (including any products, user privileges, tools required, files prepared, web server configurations, or any other initial conditions to prior to initiating the proof of concept)\u003c/li\u003e\n\u003cli\u003eReproduction steps including vulnerable endpoints, parameters, payloads used, source of any scripts used, or command line inputs (burp requests, screenshots and recordings are \u003cstrong\u003ehighly\u003c/strong\u003e encouraged)\u003c/li\u003e\n\u003cli\u003eExpected results/behavior vs actual results/behavior (include any formal documentation, resources, or links that state the expected behavior)\u003c/li\u003e\n\u003cli\u003eAssessed security impact (as it relates to the Confidentiality, Integrity, and/or Availability of the product)\u003c/li\u003e\n\u003cli\u003ePossible mitigations, fixes, or security controls\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003ePublic Disclosure\u003c/h3\u003e\n\n\u003cp\u003eAt Atlassian, one of our values is Open Company, No Bullshit, we believe that vulnerability disclosure is a part of that value. We hold ourselves to the security bug fix service level objectives, found \u003ca href=\"https://www.atlassian.com/trust/security/bug-fix-policy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e, and will accept disclosure requests in the bug bounty program after the issue has been fixed and released in production. However, if the report contains any information regarding a customer instance or data the request will be rejected. If you are planning to disclose outside of the bug bounty, we ask that you give us reasonable notice and wait until the \u003ca href=\"https://www.atlassian.com/trust/security/bug-fix-policy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eassociated SLO\u003c/a\u003e has passed.  \u003c/p\u003e\n\n\u003ch3\u003eSafe Harbor\u003c/h3\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYou are expected, as always, to comply with all applicable laws.\u003cbr\u003e\nIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further.\u003c/p\u003e\n\n\u003ch3\u003eRewards:\u003c/h3\u003e\n\n\u003cp\u003eAny finding that is not listed in the above tiers can still be reported via this program. These reports will be rewarded as kudos only reports - any payout is at the discretion of the Opsgenie Security Team. \u003c/p\u003e\n\n\u003cp\u003eNote: Opsgenie uses \u003ca href=\"https://www.atlassian.com/trust/security/security-severity-levels\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCVSS\u003c/a\u003e to consistently score security vulnerabilities. Where discrepancies between the VRT and CVSS score exist, Opsgenie will defer to the CVSS score to determine the priority.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"243433b4-9f0d-4936-856b-ffe96dc07d62","name":"In Scope","targets":[{"id":"47243174-7327-4a21-8614-ecf0dd287c26","uri":"https://app.opsgenie.com","name":"app.opsgenie.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"37437cad-654a-4f2a-b16c-e1a2ee53ac6b","sortOrder":0},"sortOrder":0,"tags":[{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"47243174-7327-4a21-8614-ecf0dd287c26"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"47243174-7327-4a21-8614-ecf0dd287c26"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"47243174-7327-4a21-8614-ecf0dd287c26"},{"id":"c3412833-26e7-4bbd-907f-760d9da61232","name":"Newrelic","targetId":"47243174-7327-4a21-8614-ecf0dd287c26"},{"id":"eaa69542-87cd-413a-9b74-3e75f9fb01e4","name":"Angular","targetId":"47243174-7327-4a21-8614-ecf0dd287c26"}],"recentChangeFlags":null},{"id":"a86ef939-4614-488f-ad8a-799d80d512c5","uri":"https://mobileapp.opsgenie.com","name":"mobileapp.opsgenie.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d6eee79a-254b-4642-8286-1f04fd94db7d","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a86ef939-4614-488f-ad8a-799d80d512c5"}],"recentChangeFlags":null},{"id":"cf958146-a540-4c59-9bc0-0d6958f340f0","uri":null,"name":"*.opsgenie.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b20491aa-fbc9-4bde-bfbf-27e8844d5ced","sortOrder":0},"sortOrder":0,"tags":[{"id":"6f2f82a5-9ef3-4bc5-9d86-6634e03133e1","name":"Recon","targetId":"cf958146-a540-4c59-9bc0-0d6958f340f0"},{"id":"803518dc-5ae1-4e48-8de4-5b61b42a6bd0","name":"Amazon S3","targetId":"cf958146-a540-4c59-9bc0-0d6958f340f0"},{"id":"9dd4899d-3a63-4126-8c83-c1fc1de50c25","name":"Amazon Cloudfront","targetId":"cf958146-a540-4c59-9bc0-0d6958f340f0"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"cf958146-a540-4c59-9bc0-0d6958f340f0"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"cf958146-a540-4c59-9bc0-0d6958f340f0"},{"id":"ce8ff3cd-4d54-4404-8321-6351781551a3","name":"Vue.js","targetId":"cf958146-a540-4c59-9bc0-0d6958f340f0"},{"id":"e591e8bc-d7f4-49ad-952f-98dee6c92653","name":"DNS","targetId":"cf958146-a540-4c59-9bc0-0d6958f340f0"}],"recentChangeFlags":null},{"id":"af41e551-6b5b-4002-ab44-37e82b97c576","uri":null,"name":"Opsgenie (IoS)","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"dc106064-f946-4390-a87d-b3341acdedef","sortOrder":0},"sortOrder":0,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"af41e551-6b5b-4002-ab44-37e82b97c576"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"af41e551-6b5b-4002-ab44-37e82b97c576"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"af41e551-6b5b-4002-ab44-37e82b97c576"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"af41e551-6b5b-4002-ab44-37e82b97c576"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"af41e551-6b5b-4002-ab44-37e82b97c576"}],"recentChangeFlags":null},{"id":"e59bb3b0-9f10-4b66-8a61-cae34295a043","uri":null,"name":"Opsgenie (Android)","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"459485b6-bb30-42fb-9988-8c91172ef6fb","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"e59bb3b0-9f10-4b66-8a61-cae34295a043"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"e59bb3b0-9f10-4b66-8a61-cae34295a043"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"e59bb3b0-9f10-4b66-8a61-cae34295a043"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"e59bb3b0-9f10-4b66-8a61-cae34295a043"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"25b12c97-a7cb-46b1-833c-687d865f7798","p1MaxCents":400000,"p1MinCents":400000,"p2MaxCents":150000,"p2MinCents":150000,"p3MaxCents":17500,"p3MinCents":17500,"p4MaxCents":10000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":4000,"max":4000},"2":{"min":1500,"max":1500},"3":{"min":175,"max":175},"4":{"min":100,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"e84a271c-49c3-4e2d-8a19-febc976a24fc","name":"Out of Scope","targets":[{"id":"306c3a4c-b04f-4420-be6f-669ed2ae992c","uri":null,"name":"Opsgenie Production (billing systems, third parties)","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6903b3d3-8f98-46cc-ad8a-db60cdf3e5c1","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"306c3a4c-b04f-4420-be6f-669ed2ae992c"}],"recentChangeFlags":null},{"id":"203b530e-ca48-4a9e-8ab2-7e863976538a","uri":null,"name":"Any internal or development services.","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c47baf20-243f-46d7-86f3-af0643f51e2c","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"203b530e-ca48-4a9e-8ab2-7e863976538a"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"190bdc65-fbd8-4587-a4c7-215325f87cef","code":"opsgenie","state":"in_progress","endsAt":null,"bountyId":"bdc77ad4-eb1d-4ec7-bf28-ee28a9cb04c4","startsAt":"2019-02-27T19:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/28c0/23ec/6022bc42/ddca52b471e3ce27a2d600c0b9285b1b_bounty-logo-atlassian.png","logoBackgroundColor":"#0052CC","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2019-02-27T19:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/opsgenie","changelogs":"/engagements/opsgenie/changelog","submissions":null,"announcements":"/engagements/opsgenie/announcements","hallOfFame":"/engagements/opsgenie/hall_of_fames","crowdstream":"/engagements/opsgenie/crowdstream"},"announcementsCount":2,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/opsgenie/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=opsgenie\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/opsgenie/engagement_subscribers","engagementChangelogsUrl":"/engagements/opsgenie/changelog","publishedAt":"2026-04-07T21:21:19.663Z","engagementChangelogUrl":"/engagements/opsgenie/changelog/ff365908-5159-4d8d-9895-43512891a90b","createUserFeedbacksUrl":"/engagements/opsgenie/feedbacks","engagementCrowdstreamUrl":"/engagements/opsgenie/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}