{"id":"3d6b3036-d4dd-4b62-95da-daa6bbc74137","engagementId":"f811bd05-0182-4524-9f64-827091efa72d","data":{"brief":{"id":"d3e19aea-5f50-4423-a5c5-8c56b01e80a1","name":"OWASP Java Encoder","tagline":"This project will help Java web developers defend against Cross Site Scripting!","description":"\u003cp\u003eOWASP supports many volunteers efforts to produce security libraries which at the same time are used by many companies and developers, in order to secure their applications. This bounty program for Java Encoder project run by OWASP is to determine the protection level claimed by the library and verify that indeed the protected application is not vulnerable to XSS attacks when using the library.\u003c/p\u003e\n\n\u003cp\u003eThe OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage.\u003c/p\u003e\n\n\u003ch1\u003eRewards\u003c/h1\u003e\n\n\u003cp\u003eOWASP may provide rewards to eligible reporters of qualifying vulnerabilities.\u003c/p\u003e\n\n\u003ch3\u003e\u003ca href=\"https://www.owasp.org/index.php/Get_Started_with_OWASP_Bug_Bounty\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGetting Started Guide\u003c/a\u003e\u003c/h3\u003e","industryTagId":null,"targetsOverview":"\u003cp\u003eIt may also be of use to review the source code for this project here: \u003ca href=\"https://github.com/OWASP/owasp-java-encoder\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/OWASP/owasp-java-encoder\u003c/a\u003e\u003c/p\u003e\n\n\u003ch1\u003eReport Template\u003c/h1\u003e\n\n\u003cp\u003ePlease be aware that the quality of your report is critical to your submission. To ensure that we are able to understand what you are reporting and the potential impact, please make sure your report contains the following items:\u003c/p\u003e\n\n\u003cp\u003eWhat type of issue are you reporting? Does it align to the scoped issue?\u003cbr\u003e\nHow does a user reproduce your issue? (If this contains more than a few steps, please create a video so we can attempt to perform the same steps).\u003cbr\u003e\nWhat is the impact of your issue?\u003cbr\u003e\nWhat are some scenarios where an attacker would be able to leverage this vulnerability?\u003cbr\u003e\nWhat would be your suggested fix?\u003cbr\u003e\nEligibility and Responsible Disclosure\u003c/p\u003e\n\n\u003cp\u003eWe are happy to thank everyone who submits valid reports which help us improve the security of OWASP! However, only those that meet the following eligibility requirements may receive a monetary reward: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou must be the first reporter of a vulnerability. \u003c/li\u003e\n\u003cli\u003eThe vulnerability must be a qualifying vulnerability (see below) associated with a site or application in scope (see above).\u003c/li\u003e\n\u003cli\u003eWe can’t be legally prohibited from rewarding you (for example, you can’t be a resident of or located within Cuba, Sudan, North Korea, Iran or Syria, a national of other certain countries, or on a denied parties or sanctions list). \u003c/li\u003e\n\u003cli\u003eYou may not publicly disclose the vulnerability prior to our resolution.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eAbout the OWASP Java Encoder\u003c/h1\u003e\n\n\u003cp\u003eThe OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will help Java web developers defend against Cross Site Scripting!\u003c/p\u003e\n\n\u003cp\u003eCross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts (primarily JavaScript) are injected into otherwise trusted web sites. You can read more about Cross Site Scripting here: \u003ca href=\"https://owasp.org/www-community/attacks/xss/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCross-site_Scripting_(XSS)\u003c/a\u003e. One of the primary defenses to stop Cross Site Scripting is a technique called Contextual Output Encoding. You can read more about Cross Site Scripting prevention here: \u003ca href=\"https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eXSS_(Cross_Site_Scripting)_Prevention_Cheat_Sheet\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eAs of November 2015, there are no issues submitted against this project! https://github.com/OWASP/owasp-java-encoder/issues. We actively track project issues and seek to remediate any issues that arise. The project owners feel this project is stable and ready for production use and are seeking project status promotion.\u003c/p\u003e\n\n\u003ch1\u003eAccess \u0026amp; Reporting\u003c/h1\u003e\n\n\u003cp\u003ePlease, make sure to follow the instructions to obtain a copy of the web application secured by OWASP Java Encoder project here: https://github.com/OWASP/OWASPBugBounty/tree/master/JavaEncoder When submitting a bug be sure to specify the version of the application you are using, the client the vulnerability was found on, and other unique information that might be helpful for us to reproduce the vulnerability.\u003c/p\u003e\n\n\u003cp\u003eScope\u003c/p\u003e\n\n\u003cp\u003eThe OWASP Java Encoder protects ONLY against XSS attacks, therefore the main purpose of the bounty is to attack the application only against these type of vulnerabilities.\u003c/p\u003e\n\n\u003ch1\u003eAccess\u003c/h1\u003e\n\n\u003cp\u003eTo access the application please go to\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003ca href=\"https://github.com/OWASP/OWASPBugBounty/tree/master/JavaEncoder\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/OWASP/OWASPBugBounty/tree/master/JavaEncoder\u003c/a\u003e\nAll the instructions on running the web app in your environment are provided in here.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eCredentials\u003c/h1\u003e\n\n\u003cp\u003eNo credentials are necessary to login to the application. It runs a simple HTML form with different fields protected by the OWASP Java Encoder project.\u003c/p\u003e\n\n\u003ch1\u003eFocus Areas\u003c/h1\u003e\n\n\u003cp\u003eThe following policies have been configured in this application and therefore you should focus on attacking the application with XSS attacks that\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAttempt to inject HTML code, whether in plain text or encoded\u003c/li\u003e\n\u003cli\u003eAttempt to inject Javascript code into the fields, whether plain text or encoded\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eOut-of-Scope\u003c/h1\u003e\n\n\u003cp\u003eAny type of attack with exception of XSS\u003c/p\u003e\n\n\u003cp\u003eThe following finding types are specifically excluded from the bounty:\u003c/p\u003e\n\n\u003cp\u003eEverything that is not an XSS/HTML injection such as\u003cbr\u003e\nDescriptive error messages (e.g. Stack Traces, application or server errors).\u003cbr\u003e\nFingerprinting / banner disclosure on common/public services.\u003cbr\u003e\nClickjacking and issues only exploitable through clickjacking.\u003cbr\u003e\nLogout Cross-Site Request Forgery (logout CSRF).\u003cbr\u003e\nPresence of application or web browser ‘autocomplete’ or ‘save password’ functionality.\u003cbr\u003e\nLack of Secure/HTTPOnly flags on non-sensitive Cookies.\u003cbr\u003e\nLack of Security Speedbump when leaving the site.\u003cbr\u003e\nWeak Captcha / Captcha Bypass\u003cbr\u003e\nForgot Password page brute force and account lockout not enforced.\u003cbr\u003e\nUsername / email enumeration\u003cbr\u003e\nvia Login Page error message\u003cbr\u003e\nvia Forgot Password error message\u003cbr\u003e\nMissing HTTP security headers, specifically (\u003ca href=\"https://owasp.org/www-project-secure-headers/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://owasp.org/www-project-secure-headers/\u003c/a\u003e), e.g.\u003cbr\u003e\nStrict-Transport-Security\u003cbr\u003e\nX-Frame-Options\u003cbr\u003e\nX-XSS-Protection\u003cbr\u003e\nX-Content-Type-Options\u003cbr\u003e\nContent-Security-Policy, X-Content-Security-Policy, X-WebKit-CSP\u003cbr\u003e\nContent-Security-Policy-Report-Only\u003cbr\u003e\nSSL Issues, e.g.\u003cbr\u003e\nSSL Attacks such as BEAST, BREACH, Renegotiation attack\u003cbr\u003e\nSSL Forward secrecy not enabled\u003cbr\u003e\nSSL weak / insecure cipher suites\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":"\u003cp\u003e\u0026lt;b\u0026gt;This bounty requires explicit permission to disclose the results of a submission.\u0026lt;/b\u0026gt;\u003c/p\u003e"},"scope":[{"id":"c40e922a-6987-4911-9e34-815d481409a8","name":"In scope","targets":[{"id":"9978ed26-5e45-48ba-b0c8-d181c053bf5d","uri":"https://github.com/OWASP/OWASPBugBounty/tree/master/JavaEncoder/war-files","name":"https://github.com/OWASP/OWASPBugBounty/tree/master/JavaEncoder/war-files","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6d307b4c-2aca-4b48-b768-82ddff11092e","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"9978ed26-5e45-48ba-b0c8-d181c053bf5d"}],"recentChangeFlags":null},{"id":"73f95009-e3f1-4fbc-9264-4ae2de085d44","uri":"https://github.com/OWASP/OWASPBugBounty/tree/master/JavaEncoder","name":"https://github.com/OWASP/OWASPBugBounty/tree/master/JavaEncoder","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"887c6800-8348-47e5-a41f-76d11b60fbd9","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"73f95009-e3f1-4fbc-9264-4ae2de085d44"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"f811bd05-0182-4524-9f64-827091efa72d","code":"owaspjavaencoder","state":"in_progress","endsAt":null,"bountyId":"2d55802e-fc20-4090-8347-4de2008897eb","startsAt":"2016-08-24T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":null,"methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/3c54/1191/e02f2090/e6972790f7078181d7431240a9ac04b7_owasp_logo_icon.png","logoBackgroundColor":"#2a2d40","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-01-22T18:01:52.553Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/owaspjavaencoder","changelogs":"/engagements/owaspjavaencoder/changelog","submissions":null,"announcements":"/engagements/owaspjavaencoder/announcements","hallOfFame":"/engagements/owaspjavaencoder/hall_of_fames","crowdstream":"/engagements/owaspjavaencoder/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/owaspjavaencoder/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=owaspjavaencoder\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/owaspjavaencoder/engagement_subscribers","engagementChangelogsUrl":"/engagements/owaspjavaencoder/changelog","publishedAt":"2025-01-22T18:01:52.606Z","engagementChangelogUrl":"/engagements/owaspjavaencoder/changelog/3d6b3036-d4dd-4b62-95da-daa6bbc74137","createUserFeedbacksUrl":"/engagements/owaspjavaencoder/feedbacks","engagementCrowdstreamUrl":"/engagements/owaspjavaencoder/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}