{"id":"5cf4f3ff-0610-4e20-87ae-b124f3d63dc8","engagementId":"be3fa4c0-4ada-4df9-bf46-ab9ea9413d76","data":{"brief":{"id":"cab9ac18-d714-4b60-b20d-c261e172913e","name":"Pantheon","tagline":"Website development is complex. Hosting makes it harder. Top developers, marketers, and IT pros use Pantheon to build, launch, and run all their Drupal and WordPress sites. ","description":"\u003cp\u003ePantheon is the professional website platform that gives Drupal and WordPress developers everything they need to build, launch, and run solid websites. We maintain customer privacy, security, and site availability as primary responsibilities of our operation, preferring defense in depth over reactive solutions. We strive to stay abreast of the latest state-of-the-art security developments by working with security researchers.  We appreciate the researchers' efforts to help create a more secure Internet.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003ch2\u003eIntroduction\u003c/h2\u003e\n\n\u003cp\u003ePantheon is the WebOps platform people trust to host their Drupal and WordPress sites, so we take security and privacy very seriously. If you are a security researcher and have discovered a security vulnerability in the product, we appreciate your help in disclosing it to us privately and giving us an opportunity to fix it before publishing technical details.\u003c/p\u003e\n\n\u003ch2\u003eScope\u003c/h2\u003e\n\n\u003cp\u003eThe target for this program is dashboard.pantheon.io which is the company's production environment.\u003c/p\u003e\n\n\u003cp\u003eTesting is only authorized on targets listed as In-Scope. \u003cbr\u003e\nAny domain/property of Pantheon.io not listed in the targets section is out of scope. This includes any/all subdomains not listed above. \u003cbr\u003e\nIf you believe you’re identified a vulnerability on a system outside the scope but demonstrably belongs to Pantheon, please reach out to support@bugcrowd.com before submitting. It is appreciated but note that it will be marked as “not applicable” and will not be eligible for monetary or points based compensation.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003ePlease Read the Guidelines section before running tests\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003eTarget Information\u003c/h2\u003e\n\n\u003cp\u003eThe target for this program is dashboard.pantheon.io which is the company's production environment. All other subdomains are out of scope. Reports should only reference accounts owned by the researcher. Researchers can sign up for a trial account using the instructions below.\u003c/p\u003e\n\n\u003ch2\u003eGuidelines\u003c/h2\u003e\n\n\u003cp\u003e**Reports that carry an acceptable risk but demonstrate a valid security-related behavior will be closed as informative. Submissions that don’t present a security risk, are false positives, or are out of scope will be closed as N/A. If the attack/vulnerability does not pose a significant risk to the organization and is of a more informational nature, no bounty will be rewarded\u003c/p\u003e\n\n\u003cp\u003eYou are \u003cstrong\u003eprohibited\u003c/strong\u003e from:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eExecuting or attempting to execute any Denial of Service attack \u003c/li\u003e\n\u003cli\u003eUse of automated application scanners (OWASP Zap, Burp Suite) in attack mode.\u003c/li\u003e\n\u003cli\u003eAttacking or exploiting accounts not created by you.\u003c/li\u003e\n\u003cli\u003eConducting any form of social engineering attacks against Pantheon staff.\u003c/li\u003e\n\u003cli\u003eCache poisoning attacks\u003c/li\u003e\n\u003cli\u003eExceeding a rate limit of 1 request per second for all scripted / API tests. \u003c/li\u003e\n\u003cli\u003eAttempting to upgrade your trial account to a higher subscription without payment.\u003c/li\u003e\n\u003cli\u003eKnowingly posting, transmitting, uploading, linking to, sending or storing any malware.\u003c/li\u003e\n\u003cli\u003eTesting third party applications or services that integrate with or link to Pantheon.\u003c/li\u003e\n\u003cli\u003eAttempting to rename a trial or paid account to another Pantheon customer domain\u003c/li\u003e\n\u003cli\u003eLimit scripted / API tests. They must be rate limited to 1 request per second\u003c/li\u003e\n\u003cli\u003eAdd a header to your requests when possible\u003c/li\u003e\n\u003cli\u003eRegister for free accounts when testing\u003c/li\u003e\n\u003cli\u003eCross-account access may only be attempted between accounts controlled by you.\u003c/li\u003e\n\u003cli\u003eAll communication with Pantheon should ideally be done via the BugCrowd platform.\u003c/li\u003e\n\u003cli\u003eTesting test/dev/live*.pantheon.io sites. Remember to ONLY test on free trial sites that you created yourself\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eBounty Ineligible Issues\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eSelf-xss attacks (even against yourself) is outside the scope of the program\u003c/li\u003e\n\u003cli\u003eXSS on pages where admins are intentionally given full HTML editing capabilities, such as custom theme editing\u003c/li\u003e\n\u003cli\u003eClickjacking\u003c/li\u003e\n\u003cli\u003eCookie flags\u003c/li\u003e\n\u003cli\u003eSPF, DKIM, DMARC issues\u003c/li\u003e\n\u003cli\u003eHTML Injection is an accepted risk unless you can escalate to XSS\u003c/li\u003e\n\u003cli\u003eEXIF information on images\u003c/li\u003e\n\u003cli\u003eSandbox and subdomain takeovers (unless demonstrated sensitive information then it may be accepted on a case by case basis)\u003c/li\u003e\n\u003cli\u003eTeam/organization read-only privilege escalation\u003c/li\u003e\n\u003cli\u003eDo not attempt cache poisoning attacks\u003c/li\u003e\n\u003cli\u003eDo not submit reports of SSL/TLS best practice\u003c/li\u003e\n\u003cli\u003eDo not submit reports of missing header (unless chained together to create an exploit)\u003c/li\u003e\n\u003cli\u003eDo not submit reports of logout Cross-Site Request Forgery (logout CSRF)\u003c/li\u003e\n\u003cli\u003eDo not submit reports of the presence of application or web browser \"autocomplete\" or \"save password\"\u003c/li\u003e\n\u003cli\u003eDo not submit reports regarding a lack of email verification\u003c/li\u003e\n\u003cli\u003eDo not submit reports of Wordpress or Drupal issues or vulnerabilities\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eReports of discrepancies between documented and actual workspace-level role permissions are out of scope unless they demonstrate a clear, real-world security impact.\u003c/p\u003e\n\n\u003ch2\u003eReport Formatting\u003c/h2\u003e\n\n\u003cp\u003ePlease include the following information with your submission:\u003cbr\u003e\n-Vulnerable URL - the endpoint where the vulnerability occurs\u003cbr\u003e\n-Vulnerable Parameter - if applicable, the parameter where the vulnerability occurs\u003cbr\u003e\n-Vulnerability Type - the type of the vulnerability\u003cbr\u003e\n-Steps to Reproduce - step-by-step information on how to reproduce the issue\u003cbr\u003e\n-Screenshots or Video - a demonstration of the attack\u003cbr\u003e\n-Attack Scenario - an example attack scenario may help demonstrate the risk and get your issue resolved faster.\u003c/p\u003e\n\n\u003ch2\u003eSign Up Process\u003c/h2\u003e\n\n\u003cp\u003eTo sign up for a Pantheon Trial Account, please use the email you used to register with BugCrowd.  For Company name please use BC-username-nn, where nn is an integer, if you need to create a new account after the trial period has ended.   Trial accounts can be created here\u003c/p\u003e\n\n\u003cp\u003eYou may sign up for an account using your personal email address but we prefer if you sign up using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e\u003c/p\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":"\u003cp\u003e\u0026lt;b\u0026gt;This bounty requires explicit permission to disclose the results of a submission.\u0026lt;/b\u0026gt;\u003c/p\u003e"},"scope":[{"id":"b3cf6634-922b-465f-9c10-de69eb660c7b","name":"In scope","targets":[{"id":"62716e93-e14e-44ff-9dd7-66a09db5f792","uri":"https://dashboard.pantheon.io","name":"https://dashboard.pantheon.io","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ef2ae428-3445-44ae-b307-0df136fc58b7","sortOrder":0},"sortOrder":0,"tags":[{"id":"4592d652-bb2d-4ab9-8720-08fe80de0dc4","name":"Backbone","targetId":"62716e93-e14e-44ff-9dd7-66a09db5f792"},{"id":"3585ef4a-cd09-429b-ad25-5777064e59c5","name":"Moment.js","targetId":"62716e93-e14e-44ff-9dd7-66a09db5f792"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"62716e93-e14e-44ff-9dd7-66a09db5f792"},{"id":"6481be19-8d64-4bb2-8426-2f1f7afe32e6","name":"Modernizr","targetId":"62716e93-e14e-44ff-9dd7-66a09db5f792"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"e118e894-5c22-4994-ae26-c666d7738942","p1MaxCents":50000,"p1MinCents":5000,"p2MaxCents":25000,"p2MinCents":2500,"p3MaxCents":10000,"p3MinCents":null,"p4MaxCents":7500,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":50,"max":500},"2":{"min":25,"max":250},"3":{"min":0,"max":100},"4":{"min":0,"max":75},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"be3fa4c0-4ada-4df9-bf46-ab9ea9413d76","code":"pantheon","state":"in_progress","endsAt":null,"bountyId":"ff716027-9794-4957-9da1-db4fbdde831b","startsAt":"2014-08-13T00:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/ecb1/6de7/3b2e721d/ab643de84a27a76d7787801a19d9d554_Logo_BLK_Fist.png","logoBackgroundColor":"#FFFFFF","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2014-08-13T00:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/pantheon","changelogs":"/engagements/pantheon/changelog","submissions":null,"announcements":"/engagements/pantheon/announcements","hallOfFame":"/engagements/pantheon/hall_of_fames","crowdstream":"/engagements/pantheon/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/pantheon/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=pantheon\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/pantheon/engagement_subscribers","engagementChangelogsUrl":"/engagements/pantheon/changelog","publishedAt":"2026-01-28T02:35:02.851Z","engagementChangelogUrl":"/engagements/pantheon/changelog/5cf4f3ff-0610-4e20-87ae-b124f3d63dc8","createUserFeedbacksUrl":"/engagements/pantheon/feedbacks","engagementCrowdstreamUrl":"/engagements/pantheon/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}