{"id":"7a32e8b8-dceb-4cda-a9f2-a63b0a4feb31","engagementId":"cc18f70d-8637-4a94-bf11-aeb635ca0518","data":{"brief":{"id":"d74b3de3-ca0e-4790-8da7-98362b568589","name":"OWASP CSRFGuard","tagline":"Open Web Application Security Project","description":"\u003cp\u003eOWASP supports many volunteers efforts to produce security libraries which at the same time are used by many companies and developers, in order to secure their applications. This bounty program for CRSFGuard run by OWASP is to determine the protection level claimed by the library and verify that indeed the protected application is not vulnerable to CRSF attacks when using the library.\u003c/p\u003e\n\n\u003ch2\u003eRewards\u003c/h2\u003e\n\n\u003cp\u003eOWASP may provide rewards to eligible reporters of qualifying vulnerabilities. \u003c/p\u003e\n\n\u003ch2\u003eAbout OWASP CSRFGuard\u003c/h2\u003e\n\n\u003cp\u003eThe OWASP CSRFGuard library is integrated through the use of a JavaEE Filter and exposes various automated and manual ways to integrate per-session or pseudo-per-request tokens into HTML.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOWASP CSRFGuard implements a variant of the synchronizer token pattern to mitigate the risk of CSRF attacks. In order to implement this pattern, CSRFGuard must offer the capability to place the CSRF prevention token within the HTML produced by the protected web application. CSRFGuard 3 provides developers more fine grain control over the injection of the token. Developers can inject the token in their HTML using either dynamic JavaScript DOM manipulation or a JSP tag library. CSRFGuard no longer intercepts and modifies the HttpServletResponse object as was done in previous releases. The currently available token injection strategies are designed to make the integration of CSRFGuard more feasible and scalable within current enterprise web applications. Developers are encouraged to make use of both the JavaScript DOM Manipulation and the JSP tag library strategies for a complete token injection strategy. The JavaScript DOM Manipulation strategy is ideal as it is automated and requires minimal effort on behalf of the developer. In the event the JavaScript solution is insufficient within a particular application context, developers should leverage the JSP tag library. The purpose of this article is to describe the token injection strategies offered by OWASP CSRFGuard 3.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003e\u003ca href=\"https://www.owasp.org/index.php/Get_Started_with_OWASP_Bug_Bounty\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGetting Started Guide\u003c/a\u003e\u003c/h3\u003e","industryTagId":null,"targetsOverview":"\u003ch3\u003eAccess \u0026amp; Reporting\u003c/h3\u003e\n\n\u003cp\u003eWhen submitting a bug be sure to specify the version of the application you are using, the client the vulnerability was found on, and other unique information that might be helpful for us to reproduce the vulnerability. \u003c/p\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cp\u003eThe program focuses on finding CSRF attacks ONLY of the following form:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eJS token injector not properly injecting into the dom [1]\u003c/li\u003e\n\u003cli\u003eToken with weak crypto [1]\u003c/li\u003e\n\u003cli\u003eServer side not enforcing the token properly on POST Request [1]\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e[1] Excluding CSRF attacks with the help of XSS.\u003c/p\u003e\n\n\u003ch3\u003eOut-of-Scope\u003c/h3\u003e\n\n\u003cp\u003eThe CSRFGuard library purpose is to protect against CRSF attacks - therefore any other kind of vulnerability is excluded from this program\u003c/p\u003e\n\n\u003ch3\u003eNon-Qualifying Vulnerabilities\u003c/h3\u003e\n\n\u003cp\u003eThe following issues are outside the scope of our vulnerability rewards program (either ineligible or false positives):\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAttacks requiring physical access to a user's device\u003c/li\u003e\n\u003cli\u003eForms missing CSRF tokens (we require evidence of actual CSRF vulnerability)\u003c/li\u003e\n\u003cli\u003eInvalid or missing SPF (Sender Policy Framework) records\u003c/li\u003e\n\u003cli\u003eContent spoofing / text injection\u003c/li\u003e\n\u003cli\u003eBypass of URL malware detection\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users of outdated or unpatched browsers and platforms\u003c/li\u003e\n\u003cli\u003eIssues without clearly identified security impact, such as clickjacking on a static website, missing security headers, or descriptive error messages\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eReport Template\u003c/h3\u003e\n\n\u003cp\u003ePlease be aware that the quality of your report is critical to your submission. To ensure that we are able to understand what you are reporting and the potential impact, please make sure your report contains the following items. You might want to consider using this as a template or checklist when writing up your report. \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhat type of issue are you reporting? Does it align to the scoped issue?\u003c/li\u003e\n\u003cli\u003eHow does a user reproduce your issue? (If this contains more than a few steps, please create a video so we can attempt to perform the same steps).\u003c/li\u003e\n\u003cli\u003eWhat is the impact of your issue?\u003c/li\u003e\n\u003cli\u003eWhat are some scenarios where an attacker would be able to leverage this vulnerability?\u003c/li\u003e\n\u003cli\u003eWhat would be your suggested fix?\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eEligibility and Responsible Disclosure\u003c/h3\u003e\n\n\u003cp\u003eWe are happy to thank everyone who submits valid reports which help us improve the security of OWASP! However, only those that meet the following eligibility requirements may receive a monetary reward: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou must be the first reporter of a vulnerability. \u003c/li\u003e\n\u003cli\u003eThe vulnerability must be a qualifying vulnerability (see below) associated with a site or application in scope (see above).\u003c/li\u003e\n\u003cli\u003eWe can’t be legally prohibited from rewarding you (for example, you can’t be a resident of or located within Cuba, Sudan, North Korea, Iran or Syria, a national of other certain countries, or on a denied parties or sanctions list). \u003c/li\u003e\n\u003cli\u003eYou may not publicly disclose the vulnerability prior to our resolution.\u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":"\u003cp\u003e\u0026lt;b\u0026gt;This bounty requires explicit permission to disclose the results of a submission.\u0026lt;/b\u0026gt;\u003c/p\u003e"},"scope":[{"id":"0bc3221a-8b02-4943-9eea-4b2d4edc79dd","name":"In scope","targets":[{"id":"d32f0aff-fa0d-4a95-93a7-297bd81c7cf3","uri":"https://github.com/OWASP/OWASPBugBounty/tree/master/CRSFGuard","name":"https://github.com/OWASP/OWASPBugBounty/tree/master/CRSFGuard","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"642d40a1-0478-492b-95a5-2eaae2d745a8","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d32f0aff-fa0d-4a95-93a7-297bd81c7cf3"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"cc18f70d-8637-4a94-bf11-aeb635ca0518","code":"owaspcrsfguard","state":"in_progress","endsAt":null,"bountyId":"fc8697a5-b6a3-4624-9736-65625f490ed7","startsAt":"2016-07-11T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":null,"methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/744a/2faa/0b31975c/ab8da8e600311248a66e05d165103ec2_owasp_logo_flat2_icon.png","logoBackgroundColor":"#0f1854","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-01-22T18:02:14.723Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/owaspcrsfguard","changelogs":"/engagements/owaspcrsfguard/changelog","submissions":null,"announcements":"/engagements/owaspcrsfguard/announcements","hallOfFame":"/engagements/owaspcrsfguard/hall_of_fames","crowdstream":"/engagements/owaspcrsfguard/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/owaspcrsfguard/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=owaspcrsfguard\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/owaspcrsfguard/engagement_subscribers","engagementChangelogsUrl":"/engagements/owaspcrsfguard/changelog","publishedAt":"2025-01-22T18:02:14.769Z","engagementChangelogUrl":"/engagements/owaspcrsfguard/changelog/7a32e8b8-dceb-4cda-a9f2-a63b0a4feb31","createUserFeedbacksUrl":"/engagements/owaspcrsfguard/feedbacks","engagementCrowdstreamUrl":"/engagements/owaspcrsfguard/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}