{"id":"a9af7b0b-4ddd-4c19-9f43-2d14b78f1a0a","engagementId":"b91793d6-b89e-479c-bec7-f9e6b073f01c","data":{"brief":{"id":"e7ec5779-619b-452e-a7ef-2f03ecd0cfe6","name":"ProjectBalm","tagline":"Please submit your findings to Project Balm's bug bounty","description":"\u003cp\u003e\u003cstrong\u003eThis bounty is part of the Atlassian Marketplace Bounty Program\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eProjectBalm produces Risk Register, an app that allows customers to record risks, assess their magnitude, assign them to team members, comment on them, and collaborate with others on their treatment.\u003c/p\u003e\n\n\u003ch4\u003eQuick Links\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003e  \u003ca href=\"https://marketplace.atlassian.com/apps/1213146/risk-register?hosting=cloud\u0026amp;tab=overview\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eRisk Register App\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cp\u003eBelow is a list of some of the vulnerability classes that we are seeking reports for:\u003c/p\u003e\n\n\u003cp\u003e• Server Security Misconfiguration\u003cbr\u003e\n• Server-Side Injection\u003cbr\u003e\n• Broken Authentication and Session Management\u003cbr\u003e\n• Sensitive Data Exposure\u003cbr\u003e\n• Insecure OS/Firmware\u003cbr\u003e\n• Broken Cryptography\u003cbr\u003e\n• Automotive Security Misconfiguration\u003cbr\u003e\n• Cross-Site Scripting (XSS)\u003cbr\u003e\n• Broken Access Control (BAC)\u003cbr\u003e\n• Cross-Site Request Forgery (CSRF)\u003cbr\u003e\n• Application-Level Denial-of-Service (DoS)\u003cbr\u003e\n• Client-Side Injection\u003cbr\u003e\n• Unvalidated Redirects and Forwards\u003cbr\u003e\n• Insufficient Security Configurability\u003cbr\u003e\n• Insecure Data Storage\u003cbr\u003e\n• Insecure Data Transport\u003cbr\u003e\n• Privacy Concerns\u003cbr\u003e\n• External Behavior\u003cbr\u003e\n• Lack of Binary Hardening\u003cbr\u003e\n• Network Security Misconfiguration\u003cbr\u003e\n• Mobile Security Misconfiguration\u003cbr\u003e\n• Indicators of Compromise\u003c/p\u003e","industryTagId":null,"targetsOverview":"\u003ch3\u003eRules, Exclusions, and Scopes\u003c/h3\u003e\n\n\u003cp\u003eAny domain/property of ProjectBalm not listed in the targets section is strictly out of scope (for more information please see the out of scope and exclusions sections below). \u003c/p\u003e\n\n\u003ch2\u003eCreating Your Instance\u003c/h2\u003e\n\n\u003cp\u003eTo access the instance and start your testing (after you've read and understood the scope and exclusions listed below, of course) you can follow the below steps:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCreate a Jira Cloud Instance\n\n\u003cul\u003e\n\u003cli\u003eNavigate to the checkout page \u003ca href=\"https://www.atlassian.com/ondemand/signup/form?product=confluence.ondemand,jira-software.ondemand,jira-servicedesk.ondemand\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eClick \"Next\"\u003c/li\u003e\n\u003cli\u003eComplete the form, using the following format: \u003cstrong\u003ebugbounty-test-\u0026lt;bugcrowd-name\u0026gt;\u003c/strong\u003e\nNote that \u0026lt;bugcrowd-name\u0026gt; should be replaced with your own Bugcrowd username \u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eClick \"Start now\"\u003c/li\u003e\n\u003cli\u003eClick on Jira Settings\u003c/li\u003e\n\u003cli\u003eClick on Apps\u003c/li\u003e\n\u003cli\u003eType “Risk Register” in search box\u003c/li\u003e\n\u003cli\u003eClick on “Try it free”\u003c/li\u003e\n\u003cli\u003eFollowing installation instructions on screen. \u003c/li\u003e\n\u003cli\u003eFurther documentation is available \u003ca href=\"http://docs.projectbalm.com/risk-register-documentation-(cloud)\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cp\u003eAnything not declared as a target or in scope above should be considered out of scope for the purposes of this bug bounty. However to help avoid grey areas, below are examples of what is considered out of scope.\u003c/p\u003e\n\n\u003cp\u003e• Using Components with Known Vulnerabilities\u003c/p\u003e\n\n\u003ch2\u003eRules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou must ensure that customer data is not affected in any way as a result of your testing. Please ensure you're being non-destructive whilst testing and are only testing on instances that you own.\u003c/li\u003e\n\u003cli\u003eIn addition to above, customer instances are not to be accessed in any way (i.e. no customer data is accessed, customer credentials are not to be used or \"verified\")\u003c/li\u003e\n\u003cli\u003eIf you believe you have found sensitive customer data (e.g., login credentials, API keys etc) or a way to access customer data (i.e. through a vulnerability) report it, but do not attempt to successfully validate if/that it works.\u003c/li\u003e\n\u003cli\u003e\n\u003cem\u003eUse of any automated tools/scanners is strictly prohibited\u003c/em\u003e and will lead to you being removed from the program (trust us, we have those tools too).\u003c/li\u003e\n\u003cli\u003eReports need to be submitted in plain text (associated pictures/videos are fine as long as they're in standard formats). Non-plain text reports (e.g. PDF, DOCX) will be asked to be resubmitted in plain text.\u003c/li\u003e\n\u003cli\u003eGrants/awards are at the discretion of ProjectBalm and we withhold the right to grant, modify or deny grants. But we'll be fair about it.\u003c/li\u003e\n\u003cli\u003eTax implications of any payouts are the sole responsibility of the reporter.\u003c/li\u003e\n\u003cli\u003eDo NOT conduct non-technical attacks such as social engineering, phishing or unauthorized access to infrastructure.\u003c/li\u003e\n\u003cli\u003eDo NOT test the physical security of ProjectBalm offices, employees, equipment, etc.\u003c/li\u003e\n\u003cli\u003eThis bounty follows Bugcrowd’s standard disclosure terms.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003ePublic Disclosure\u003c/h3\u003e\n\n\u003cp\u003eBefore disclosing an issue publicly we require that you first request permission from us.\u003cbr\u003e\nProjectBalm will process requests for public disclosure on a per report basis. Requests to publicly disclose an issue that has not yet been fixed for customers will be rejected. Any researcher found publicly disclosing reported vulnerabilities without ProjectBalm’s written consent will have any allocated bounty withdrawn and disqualified from the program.\u003c/p\u003e\n\n\u003ch3\u003eSafe Harbor\u003c/h3\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYou are expected, as always, to comply with all applicable laws.\u003cbr\u003e\nIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"10bb34e7-ede3-41ca-8420-2ee64eab72f1","name":"In Scope Targets","targets":[{"id":"b620b53b-e48d-4dcb-b454-ef3fa86bc7dc","uri":"https://marketplace.atlassian.com/apps/1213146/risk-register?hosting=cloud","name":"https://marketplace.atlassian.com/apps/1213146/risk-register?hosting=cloud","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"444ac6e9-214b-44ae-bcb3-d7fdca98e2b2","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b620b53b-e48d-4dcb-b454-ef3fa86bc7dc"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"c834570f-26c6-44e1-9bba-5edeaba825fa","p1MaxCents":150000,"p1MinCents":150000,"p2MaxCents":90000,"p2MinCents":90000,"p3MaxCents":30000,"p3MinCents":30000,"p4MaxCents":10000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":1500,"max":1500},"2":{"min":900,"max":900},"3":{"min":300,"max":300},"4":{"min":100,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"b91793d6-b89e-479c-bec7-f9e6b073f01c","code":"projectbalm","state":"in_progress","endsAt":null,"bountyId":"b83a7add-3cad-4f41-a4d0-dc7ba64664d5","startsAt":"2020-07-07T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":null,"methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/engagement_brief_logos/engagement_brief/logo/e7ec5779-619b-452e-a7ef-2f03ecd0cfe6/1aa8303f-2439-4e4a-b1be-6e6e1cca951c.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2020-07-07T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/projectbalm","changelogs":"/engagements/projectbalm/changelog","submissions":null,"announcements":"/engagements/projectbalm/announcements","hallOfFame":"/engagements/projectbalm/hall_of_fames","crowdstream":"/engagements/projectbalm/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/projectbalm/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=projectbalm\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/projectbalm/engagement_subscribers","engagementChangelogsUrl":"/engagements/projectbalm/changelog","publishedAt":"2026-03-12T14:53:12.123Z","engagementChangelogUrl":"/engagements/projectbalm/changelog/a9af7b0b-4ddd-4c19-9f43-2d14b78f1a0a","createUserFeedbacksUrl":"/engagements/projectbalm/feedbacks","engagementCrowdstreamUrl":"/engagements/projectbalm/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}