{"id":"5d1e9957-4ace-4443-a0ab-936de2c7234d","engagementId":"f92bc39f-cd11-4531-8000-f32c61535f00","data":{"brief":{"id":"0719e4e4-b748-4663-b099-16498f14d9a1","name":"Progress Software RAG","tagline":"Progress Software (Nasdaq: PRGS) helps organizations achieve transformational success during disruptive change by providing software that enables customers to develop, deploy, and manage their solutions.","description":"\u003cp\u003eNo technology is perfect and Progress Software believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our application. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Progress not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Progress, you can report it to this engagement. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eReport Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eReports must contain a clear explanation of the issue and the security impact along with detailed steps to reproduce it. If the issue cannot be reliably reproduced based on your report, it may be considered ineligible for a reward\u003c/li\u003e\n\u003cli\u003eDo not submit more than one vulnerability per report. In cases where demonstrating impact requires chaining multiple vulnerabilities together, those can be included in the same report as long as the linkage is clearly explained\u003c/li\u003e\n\u003cli\u003eWe do not accept reports that contain low-effort or AI-generated content. Submissions must demonstrate original analysis, clear understanding of the issue, and actionable detail. Reports lacking meaningful human input will be rejected\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eNote: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAccounts expire after 14 days but additional accounts can be created using an alias of you initial account\u003c/li\u003e\n\u003cli\u003eUpgraded accounts can ONLY be requested when you submit a report containing a security vulnerability that you were able to produce. Please provide your email within the comments. \n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eRequests not associated with a security report will not be honored\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003eTo support your testing, we’ve highlighted several key areas of interest. While we ask that you report any efforts related to these areas, please note that testing is not limited to them. Submissions outside of these focus areas are equally welcomed and appreciated.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorization layer \u003c/li\u003e\n\u003cli\u003eNucliaDB: as a multi-tenant database, it might be possible to access data for another clients \u003c/li\u003e\n\u003cli\u003eValidation and API limits in general \u003c/li\u003e\n\u003cli\u003eLLM drivers, particularly OpenAI compatible and HuggingFace \u003c/li\u003e\n\u003cli\u003eCommunication between regional clusters (where data is stored) push/pull accounting data with the global control plan (billing) is done through the public internet. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 14 days has gone by\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2025, we would consider it in-scope on 01/15/2025\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eLeaked Credentials\u003c/h2\u003e\n\n\u003cp\u003eIf you happen to identify vulnerabilities involving data that has been exposed or leaked such as dark web forums or leaked credential sites. You can report it to this engagement. However, be aware that it is only eligible for points-based compensation. This policy helps maintain the highest standard of operational confidentiality, integrity, and compliance.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eInteracting or manipulating other stakeholders and their associated accounts including:\n\n\u003cul\u003e\n\u003cli\u003eSocial engineering attacks\u003c/li\u003e\n\u003cli\u003ePhishing attacks\u003c/li\u003e\n\u003cli\u003ePhysical attacks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eIf you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity.\u003c/li\u003e\n\u003cli\u003eThird party providers and services\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\n\n\u003cul\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting\u003c/li\u003e\n\u003cli\u003eEmail bombing/flooding\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSocial Engineering\n\n\u003cul\u003e\n\u003cli\u003eFor example, attempts to steal cookies, fake login pages to collect credentials.\u003c/li\u003e\n\u003cli\u003ePhishing.\u003c/li\u003e\n\u003cli\u003ePhysical attacks against Facilities / Property.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eCredential Stuffing / Password Spraying.\u003c/li\u003e\n\u003cli\u003eAny type of brute force attacks.\u003c/li\u003e\n\u003cli\u003eClickjacking\u003c/li\u003e\n\u003cli\u003eSubmissions related to past or present data dumps or leaked credentials.\u003c/li\u003e\n\u003cli\u003eEngaging in the trade of stolen/breached user credentials or use leaked credentials dumps in the testing.\u003c/li\u003e\n\u003cli\u003eModifying data residing in an account that does not belong to you.\u003c/li\u003e\n\u003cli\u003eAccessing or downloading data beyond the minimum required to demonstrate a vulnerability.\u003c/li\u003e\n\u003cli\u003eMaking any changes to the system configurations, files, or data.\u003c/li\u003e\n\u003cli\u003eIntroducing a backdoor in any system.\u003c/li\u003e\n\u003cli\u003eAttacking/interacting with our end users in any way.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eDisclosure Policy\u003c/h2\u003e\n\n\u003cp\u003ePlease do not discuss any vulnerabilities (even resolved ones) outside of the program without express consent from the organization.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"1e5e3074-3cfb-4dea-a497-051abf7ddc1e","name":"In Scope","targets":[{"id":"2af14fe7-e760-463e-a8c9-9739b150c3df","uri":"https://stashify.cloud","name":"https://stashify.cloud","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e08d5d92-9e9a-4d77-9e19-aa09b3ad388c","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"2af14fe7-e760-463e-a8c9-9739b150c3df"},{"id":"1f10e73e-4eef-42c1-ba6b-6df69f8dc8fa","name":"Rust","targetId":"2af14fe7-e760-463e-a8c9-9739b150c3df"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2af14fe7-e760-463e-a8c9-9739b150c3df"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"2af14fe7-e760-463e-a8c9-9739b150c3df"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch2\u003eInformation\u003c/h2\u003e\n\n\u003cp\u003eMost functionalities can be accessed through NucliaDB which will call to other components internally. All ~200 endpoints are REST-like HTTP and listed \u003ca href=\"https://docs.rag.progress.cloud/docs/develop/intro\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e\u003c/p\u003e\n\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\n\u003cp\u003e\u003ca href=\"https://docs.rag.progress.cloud/docs/develop/intro\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eDeveloper\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003eSource code (for some components) available at: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nuclia/nucliadb\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNucliaDB\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nuclia/sync-agent\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSync Agent\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nuclia/nuclia.py\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSDK\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nuclia/frontend\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eFrontend\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"f92bc39f-cd11-4531-8000-f32c61535f00","code":"progresssoftware-rag","state":"in_progress","endsAt":null,"bountyId":"043997e3-b75b-476c-a1f3-7a81c54aaf0d","startsAt":"2026-01-27T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/a973/7f6c/9ebc6004/c144de2aff06202c63bc88aeeb2e11a9_progress_software_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-01-27T18:00:00.431Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/progresssoftware-rag","changelogs":"/engagements/progresssoftware-rag/changelog","submissions":null,"announcements":"/engagements/progresssoftware-rag/announcements","hallOfFame":"/engagements/progresssoftware-rag/hall_of_fames","crowdstream":"/engagements/progresssoftware-rag/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/progresssoftware-rag/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=progresssoftware-rag\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/progresssoftware-rag/engagement_subscribers","engagementChangelogsUrl":"/engagements/progresssoftware-rag/changelog","publishedAt":"2026-01-27T18:00:00.464Z","engagementChangelogUrl":"/engagements/progresssoftware-rag/changelog/5d1e9957-4ace-4443-a0ab-936de2c7234d","createUserFeedbacksUrl":"/engagements/progresssoftware-rag/feedbacks","engagementCrowdstreamUrl":"/engagements/progresssoftware-rag/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}