{"id":"1a2d4655-56f5-4c58-a543-cd511c1ddb7c","engagementId":"13417475-b7ef-44cd-b210-c3f8f316ed7d","data":{"brief":{"id":"6e319396-ac18-4ae9-8cfe-dd36073bd079","name":"Requirement Yogi (Bug bounty)","tagline":"Submit your finding to Requirement Yogi's bug bounty program","description":"\u003ch2\u003eHow to install\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.atlassian.com/ondemand/signup/form?product=confluence.ondemand,jira-software.ondemand,jira-servicedesk.ondemand\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNavigate to this checkout page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eComplete the form using an URL \u003ccode\u003ebugbounty-test-\u0026lt;bugcrowd-name\u0026gt;.atlassian.net\u003c/code\u003e and an email \u003ccode\u003e@bugcrowdninja.com\u003c/code\u003e,\u003c/li\u003e\n\u003cli\u003eGo to Apps -\u0026gt; Find new apps -\u0026gt; Install \"Requirement Yogi for Confluence\" and \"Requirement Yogi for Jira\",\u003c/li\u003e\n\u003cli\u003eUse an evaluation license (duration: 1 month),\u003c/li\u003e\n\u003cli\u003eCheckout our \u003ca href=\"https://docs.requirementyogi.com/cloud/installation-checklist\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eInstallation Checklist\u003c/a\u003e and our \u003ca href=\"https://docs.requirementyogi.com/cloud/tutorials\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGetting started tutorials\u003c/a\u003e,\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eMore documentation\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe publish our OpenAPI files, see https://docs.requirementyogi.com/cloud/rest-apis,\u003c/li\u003e\n\u003cli\u003eOur three main apps point to the same backend data: https://confluence.requirementyogi.com (the Confluence app's backend), https://jira.requirementyogi.com (the Jira app's backend), and https://app.requirementyogi.com (the standalone app).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eDefinitions\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\"\u003cem\u003eData\u003c/em\u003e\" means the contents of requirements, usernames, emails, contents (including the title) of pages, contents (including the title) of issues,\u003c/li\u003e\n\u003cli\u003e\"\u003cem\u003eMetadata\u003c/em\u003e\" means the issue keys, requirement keys, space keys, space ids, page ids, names of categories, etc.\u003c/li\u003e\n\u003cli\u003e\"\u003cem\u003eLong\u003c/em\u003e\" means an integer with a length of 64 bits.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eVulnerability ranking\u003c/h2\u003e\n\n\u003ch3\u003eP1 - Theft of secrets, RCE\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities that allow Remote Code Execution.\u003c/li\u003e\n\u003cli\u003eVulnerabilities that allow an attacker to impersonate the app to access data hosted by Atlassian without using our servers (e.g., Stealing secret tokens).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eP2 - Cross-tenant security\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities that allow an attacker to \u003cstrong\u003eview or edit Data belonging to another customer\u003c/strong\u003e.\n\n\u003cul\u003e\n\u003cli\u003eExclusion: \u003cem\u003eMetadata\u003c/em\u003e, as defined in the \"Definitions\" section (downgraded as P4),\u003c/li\u003e\n\u003cli\u003eExclusion: Data access vulnerabilities that rely on brute-forcing a highly entropic UUID or Long are capped at P3,\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eP3 - Same-tenant privilege escalation\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities that allow a user to \u003cstrong\u003ebypass the permission checks\u003c/strong\u003e and view or edit the data of another user of the same customer.\n\n\u003cul\u003e\n\u003cli\u003eExclusion: Page restrictions are not used in Requirement Yogi, only space permissions are used.\u003c/li\u003e\n\u003cli\u003eExclusion: Confluence/Jira permissions are cached for 30 minutes.\u003c/li\u003e\n\u003cli\u003eExclusion: \u003cem\u003eMetadata\u003c/em\u003e, as defined in the \"Definitions\" section (downgraded as P4),\u003c/li\u003e\n\u003cli\u003eExclusion: Requirement keys are visible in Jira for any viewer of the issue, even if the user cannot view the requirement.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerabilities that rely on brute-forcing a highly entropic UUID or Long,\u003c/li\u003e\n\u003cli\u003eVulnerabilities that allow an attacker to \u003cstrong\u003edisplay false information\u003c/strong\u003e to another customer. Example: A reflection vulnerability.\u003c/li\u003e\n\u003cli\u003eAny other vulnerability that is ranked P3 or above on \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugCrowd's taxonomy\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eP4 - Low\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities on \u003cem\u003eMetadata\u003c/em\u003e,\u003c/li\u003e\n\u003cli\u003eMinor security flaws that affect singular users and require significant user interaction or specific prerequisites like a Man-in-the-Middle (MitM) position,\u003c/li\u003e\n\u003cli\u003eAny vulnerability ranked P4 or above on \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugCrowd's taxonomy\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eP5 - Informational / Non-Exploitable\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny vulnerability ranked P5 or above on \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugCrowd's taxonomy\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eVulnerabilities that can't be immediately exploited, but \u003cstrong\u003epose a security risk\u003c/strong\u003e in other circumstances.\n\n\u003cul\u003e\n\u003cli\u003eExclusion: The contents of error messages.\u003c/li\u003e\n\u003cli\u003eNote: These vulnerabilities will often be downgraded if we have already mitigated against this risk.\u003c/li\u003e\n\u003cli\u003eExamples: Remote code execution which didn't succeed to access sensitive information, access to database credentials but the database is properly isolated in a private network.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRules, Exclusions, and Scopes\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003ePlease only test using instances with the URL \u003ccode\u003ebugbounty-test-\u0026lt;bugcrowd-name\u0026gt;.atlassian.net\u003c/code\u003e. Please do not create additional instances outside of this namespace for testing.\u003c/li\u003e\n\u003cli\u003eDo not test marketplace.atlassian.com, but install our apps and test the apps themselves.\u003c/li\u003e\n\u003cli\u003eDo not post reviews for our apps on marketplace.atlassian.com. Failure to adhere to this will result in not receiving any reward for any of your submissions and possible removal from the program.\u003c/li\u003e\n\u003cli\u003eAny domain/property of Requirement Yogi not listed in the targets section is strictly out of scope (for more information please see the out of scope and exclusions sections below).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cp\u003eAnything not declared as a target or in scope above should be considered out of scope for the purposes of this bug bounty. \u003cstrong\u003eSpecifically for Requirement Yogi\u003c/strong\u003e:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePage-level restrictions are not applied. Requirements on a restricted page are visible to everyone in the space.\u003c/li\u003e\n\u003cli\u003eConfluence administrators can always view all requirements,\u003c/li\u003e\n\u003cli\u003eIt is possible to change images inside of a requirement by pointing to a URL and swapping the image under the URL,\u003c/li\u003e\n\u003cli\u003ePermissions (retrieved from Confluence or Jira) are cached for 30 minutes (as mentioned in P4),\u003c/li\u003e\n\u003cli\u003eIt is possible to view all requirement keys as a simple user with access to Confluence, but not their content.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eTo help avoid grey areas, below are examples of what is considered out of scope.\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eBlind XSS must not return any user data that you do not have access to (e.g. Screen shots, cookies that aren't owned by you, etc); when testing for blind XSS, please use the least invasive test possible (e.g. calling 1x1 image or nonexistent page on your webserver, etc).\u003c/li\u003e\n\u003cli\u003eWhen testing, please exercise caution if injecting on any form that may be publicly visible - such as forums, etc. Before injection, please make sure your payload can be removed from the site. If it cannot be easily removed, please check with support@bugcrowd before performing the testing. \u003c/li\u003e\n\u003cli\u003eNo pivoting or post exploitation attacks (i.e. using a vulnerability to find another vulnerability) are allowed on this program. DO NOT under any circumstance leverage a finding to identify further issues.\u003c/li\u003e\n\u003cli\u003eAny Requirement Yogi website is out of scope for this bounty unless it is a subdomain directly accessible from one of the targets or any associated services attached to the instance.\u003c/li\u003e\n\u003cli\u003eCustomer cloud instances and data are explicitly out of scope.\u003c/li\u003e\n\u003cli\u003eAny repository that you are not an owner of - do not impact Requirement Yogi or Atlassian customers in any way.\u003c/li\u003e\n\u003cli\u003eOnly the latest version of our products are eligible for a reward.\u003c/li\u003e\n\u003cli\u003eAny internal or development services.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eThe following finding types are specifically excluded from the bounty:\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eLack of Rate Limiting on any of the targets.\u003c/li\u003e\n\u003cli\u003eThe use of high-volume, disruptive automated scanners is prohibited. If you use automated tools (like Burp Suite Active Scan), you must strictly rate-limit your requests to avoid degrading our service. Volumetric/DoS attacks will result in immediate removal from the program.\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g. Stack Traces, application or server errors).\u003c/li\u003e\n\u003cli\u003eFingerprinting / banner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eLogout Cross-Site Request Forgery (logout CSRF).\u003c/li\u003e\n\u003cli\u003eReflected Text Injection / Non-Persistent Content Spoofing (modifying text on a page via a URL parameter without XSS or persistent database changes).\u003c/li\u003e\n\u003cli\u003ePresence of application or web browser ‘autocomplete’ or ‘save password’ functionality.\u003c/li\u003e\n\u003cli\u003eLack of Secure/HTTPOnly flags on non-sensitive Cookies.\u003c/li\u003e\n\u003cli\u003eLack of Security Speedbump when leaving the site.\u003c/li\u003e\n\u003cli\u003eWeak Captcha / Captcha Bypass.\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force and account lockout not enforced.\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration.\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers, specifically (\u003ca href=\"https://owasp.org/www-project-secure-headers/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://owasp.org/www-project-secure-headers/\u003c/a\u003e), e.g.\n\n\u003cul\u003e\n\u003cli\u003eStrict-Transport-Security.\u003c/li\u003e\n\u003cli\u003eX-Frame-Options.\u003c/li\u003e\n\u003cli\u003eX-XSS-Protection.\u003c/li\u003e\n\u003cli\u003eX-Content-Type-Options.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy, X-Content-Security-Policy, X-WebKit-CSP.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy-Report-Only.\u003c/li\u003e\n\u003cli\u003eCache-Control and Pragma\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eHTTP/DNS cache poisoning.\u003c/li\u003e\n\u003cli\u003eSSL/TLS Issues, e.g.\n\n\u003cul\u003e\n\u003cli\u003eSSL Attacks such as BEAST, BREACH, Renegotiation attack.\u003c/li\u003e\n\u003cli\u003eSSL Forward secrecy not enabled.\u003c/li\u003e\n\u003cli\u003eSSL weak/insecure cipher suites.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSelf-XSS reports will not be accepted.\n\n\u003cul\u003e\n\u003cli\u003eSimilarly, any XSS where local access is required (i.e. User-Agent Header injection) will not be accepted. The only exception will be if you can show a working off-path MiTM attack that will allow for the XSS to trigger.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerabilities that are limited to unsupported browsers will not be accepted (i.e. \"this exploit only works in IE6/IE7\"). A list of supported browsers can be found \u003ca href=\"https://support.atlassian.com/atlassian-account/docs/supported-browsers-for-atlassian-cloud-products/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eKnown vulnerabilities in used libraries, or the reports that an Atlassian product uses an outdated third party library (e.g. jQuery, Apache HttpComponents etc) unless you can prove exploitability.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect SPF records of any kind.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect DMARC records of any kind.\u003c/li\u003e\n\u003cli\u003eSource code disclosure vulnerabilities.\u003c/li\u003e\n\u003cli\u003eInformation disclosure of non-confidential information (e. g. issue id, project id, commit hashes).\u003c/li\u003e\n\u003cli\u003eThe ability to upload/download viruses or malicious files to the platform.\u003c/li\u003e\n\u003cli\u003eEmail bombing/Flooding/rate limiting.\u003c/li\u003e\n\u003cli\u003eJWT in ajax requests ignores path and HTTP method.\u003c/li\u003e\n\u003cli\u003eFor some of our apps, we allow arbitrary HTML templates to be defined by administrators. Those could potentially be used for XSS attacks, however since only administrators have access we don't consider those as security threats.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou must ensure that customer data is not affected in any way as a result of your testing. Please ensure you're being non-destructive whilst testing and are only testing on instances that you own.\u003c/li\u003e\n\u003cli\u003eIn addition to above, customer instances are not to be accessed in any way (i.e. no customer data is accessed, customer credentials are not to be used or \"verified\")\u003c/li\u003e\n\u003cli\u003eIf you believe you have found sensitive customer data (e.g., login credentials, API keys etc) or a way to access customer data (i.e. through a vulnerability) report it, but do not attempt to successfully validate if/that it works.\u003c/li\u003e\n\u003cli\u003eSeveral similar reports which have the same root cause or can be resolved with the same bugfix will be counted as duplicates,\u003c/li\u003e\n\u003cli\u003eReports need to be submitted in plain text (associated pictures/videos are fine as long as they're in standard formats). Non-plain text reports (e.g. PDF, DOCX) will be asked to be resubmitted in plain text.\u003c/li\u003e\n\u003cli\u003eGrants/awards are at the discretion of Requirement Yogi and we withhold the right to grant, modify or deny grants. But we'll be fair about it.\u003c/li\u003e\n\u003cli\u003eTax implications of any payouts are the sole responsibility of the reporter.\u003c/li\u003e\n\u003cli\u003eDo NOT conduct non-technical attacks such as social engineering, phishing or unauthorized access to infrastructure.\u003c/li\u003e\n\u003cli\u003eDo NOT test the physical security of Requirement Yogi offices, employees, equipment, etc.\u003c/li\u003e\n\u003cli\u003eThis bounty follows Bugcrowd’s standard disclosure terms.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003ePublic Disclosure\u003c/h3\u003e\n\n\u003cp\u003eBefore disclosing an issue publicly we require that you first obtain consent from us. Requirement Yogi will process requests for public disclosure on a per report basis. Requests to publicly disclose an issue that has not yet been fixed for customers will be rejected. Any researcher found publicly disclosing reported vulnerabilities without Requirement Yogi's written consent will have any allocated bounty withdrawn and disqualified from the program.\u003c/p\u003e\n\n\u003ch3\u003eSafe Harbor\u003c/h3\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls used strictly during and for the purpose of your good-faith security testing;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms of Service that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eThird-Party Infrastructure: This Safe Harbor applies only to Requirement Yogi's code, domains, and data. We cannot bind Atlassian or any third-party hosting providers (e.g., AWS) to this Safe Harbor. Researchers must also adhere to Atlassian’s Acceptable Use Policy when interacting with .atlassian.net domains.\nYou are expected, as always, to comply with all applicable laws.\nIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThank you very much for your hard work.\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003ch2\u003eHow to install\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.atlassian.com/ondemand/signup/form?product=confluence.ondemand,jira-software.ondemand,jira-servicedesk.ondemand\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNavigate to this checkout page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eComplete the form using an URL \u003ccode\u003ebugbounty-test-\u0026lt;bugcrowd-name\u0026gt;.atlassian.net\u003c/code\u003e and an email \u003ccode\u003e@bugcrowdninja.com\u003c/code\u003e,\u003c/li\u003e\n\u003cli\u003eGo to Apps -\u0026gt; Find new apps -\u0026gt; Install \"Requirement Yogi for Confluence\" and \"Requirement Yogi for Jira\",\u003c/li\u003e\n\u003cli\u003eUse an evaluation license (duration: 1 month),\u003c/li\u003e\n\u003cli\u003eCheckout our \u003ca href=\"https://docs.requirementyogi.com/cloud/installation-checklist\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eInstallation Checklist\u003c/a\u003e and our \u003ca href=\"https://docs.requirementyogi.com/cloud/tutorials\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGetting started tutorials\u003c/a\u003e,\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eMore documentation\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe publish our OpenAPI files, see https://docs.requirementyogi.com/cloud/rest-apis,\u003c/li\u003e\n\u003cli\u003eOur three main apps point to the same backend data: https://confluence.requirementyogi.com (the Confluence app's backend), https://jira.requirementyogi.com (the Jira app's backend), and https://app.requirementyogi.com (the standalone app).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eDefinitions\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\"\u003cem\u003eData\u003c/em\u003e\" means the contents of requirements, usernames, emails, contents (including the title) of pages, contents (including the title) of issues,\u003c/li\u003e\n\u003cli\u003e\"\u003cem\u003eMetadata\u003c/em\u003e\" means the issue keys, requirement keys, space keys, space ids, page ids, names of categories, etc.\u003c/li\u003e\n\u003cli\u003e\"\u003cem\u003eLong\u003c/em\u003e\" means an integer with a length of 64 bits.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eVulnerability ranking\u003c/h2\u003e\n\n\u003ch3\u003eP1 - Theft of secrets, RCE\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities that allow Remote Code Execution.\u003c/li\u003e\n\u003cli\u003eVulnerabilities that allow an attacker to impersonate the app to access data hosted by Atlassian without using our servers (e.g., Stealing secret tokens).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eP2 - Cross-tenant security\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities that allow an attacker to \u003cstrong\u003eview or edit Data belonging to another customer\u003c/strong\u003e.\n\n\u003cul\u003e\n\u003cli\u003eExclusion: \u003cem\u003eMetadata\u003c/em\u003e, as defined in the \"Definitions\" section (downgraded as P4),\u003c/li\u003e\n\u003cli\u003eExclusion: Data access vulnerabilities that rely on brute-forcing a highly entropic UUID or Long are capped at P3,\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eP3 - Same-tenant privilege escalation\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities that allow a user to \u003cstrong\u003ebypass the permission checks\u003c/strong\u003e and view or edit the data of another user of the same customer.\n\n\u003cul\u003e\n\u003cli\u003eExclusion: Page restrictions are not used in Requirement Yogi, only space permissions are used.\u003c/li\u003e\n\u003cli\u003eExclusion: Confluence/Jira permissions are cached for 30 minutes.\u003c/li\u003e\n\u003cli\u003eExclusion: \u003cem\u003eMetadata\u003c/em\u003e, as defined in the \"Definitions\" section (downgraded as P4),\u003c/li\u003e\n\u003cli\u003eExclusion: Requirement keys are visible in Jira for any viewer of the issue, even if the user cannot view the requirement.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerabilities that rely on brute-forcing a highly entropic UUID or Long,\u003c/li\u003e\n\u003cli\u003eVulnerabilities that allow an attacker to \u003cstrong\u003edisplay false information\u003c/strong\u003e to another customer. Example: A reflection vulnerability.\u003c/li\u003e\n\u003cli\u003eAny other vulnerability that is ranked P3 or above on \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugCrowd's taxonomy\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eP4 - Low\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities on \u003cem\u003eMetadata\u003c/em\u003e,\u003c/li\u003e\n\u003cli\u003eMinor security flaws that affect singular users and require significant user interaction or specific prerequisites like a Man-in-the-Middle (MitM) position,\u003c/li\u003e\n\u003cli\u003eAny vulnerability ranked P4 or above on \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugCrowd's taxonomy\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eP5 - Informational / Non-Exploitable\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny vulnerability ranked P5 or above on \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugCrowd's taxonomy\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eVulnerabilities that can't be immediately exploited, but \u003cstrong\u003epose a security risk\u003c/strong\u003e in other circumstances.\n\n\u003cul\u003e\n\u003cli\u003eExclusion: The contents of error messages.\u003c/li\u003e\n\u003cli\u003eNote: These vulnerabilities will often be downgraded if we have already mitigated against this risk.\u003c/li\u003e\n\u003cli\u003eExamples: Remote code execution which didn't succeed to access sensitive information, access to database credentials but the database is properly isolated in a private network.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRules, Exclusions, and Scopes\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003ePlease only test using instances with the URL \u003ccode\u003ebugbounty-test-\u0026lt;bugcrowd-name\u0026gt;.atlassian.net\u003c/code\u003e. Please do not create additional instances outside of this namespace for testing.\u003c/li\u003e\n\u003cli\u003eDo not test marketplace.atlassian.com, but install our apps and test the apps themselves.\u003c/li\u003e\n\u003cli\u003eDo not post reviews for our apps on marketplace.atlassian.com. Failure to adhere to this will result in not receiving any reward for any of your submissions and possible removal from the program.\u003c/li\u003e\n\u003cli\u003eAny domain/property of Requirement Yogi not listed in the targets section is strictly out of scope (for more information please see the out of scope and exclusions sections below).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cp\u003eAnything not declared as a target or in scope above should be considered out of scope for the purposes of this bug bounty. \u003cstrong\u003eSpecifically for Requirement Yogi\u003c/strong\u003e:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePage-level restrictions are not applied. Requirements on a restricted page are visible to everyone in the space.\u003c/li\u003e\n\u003cli\u003eConfluence administrators can always view all requirements,\u003c/li\u003e\n\u003cli\u003eIt is possible to change images inside of a requirement by pointing to a URL and swapping the image under the URL,\u003c/li\u003e\n\u003cli\u003ePermissions (retrieved from Confluence or Jira) are cached for 30 minutes (as mentioned in P4),\u003c/li\u003e\n\u003cli\u003eIt is possible to view all requirement keys as a simple user with access to Confluence, but not their content.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eTo help avoid grey areas, below are examples of what is considered out of scope.\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eBlind XSS must not return any user data that you do not have access to (e.g. Screen shots, cookies that aren't owned by you, etc); when testing for blind XSS, please use the least invasive test possible (e.g. calling 1x1 image or nonexistent page on your webserver, etc).\u003c/li\u003e\n\u003cli\u003eWhen testing, please exercise caution if injecting on any form that may be publicly visible - such as forums, etc. Before injection, please make sure your payload can be removed from the site. If it cannot be easily removed, please check with support@bugcrowd before performing the testing. \u003c/li\u003e\n\u003cli\u003eNo pivoting or post exploitation attacks (i.e. using a vulnerability to find another vulnerability) are allowed on this program. DO NOT under any circumstance leverage a finding to identify further issues.\u003c/li\u003e\n\u003cli\u003eAny Requirement Yogi website is out of scope for this bounty unless it is a subdomain directly accessible from one of the targets or any associated services attached to the instance.\u003c/li\u003e\n\u003cli\u003eCustomer cloud instances and data are explicitly out of scope.\u003c/li\u003e\n\u003cli\u003eAny repository that you are not an owner of - do not impact Requirement Yogi or Atlassian customers in any way.\u003c/li\u003e\n\u003cli\u003eOnly the latest version of our products are eligible for a reward.\u003c/li\u003e\n\u003cli\u003eAny internal or development services.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eThe following finding types are specifically excluded from the bounty:\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eLack of Rate Limiting on any of the targets.\u003c/li\u003e\n\u003cli\u003eThe use of high-volume, disruptive automated scanners is prohibited. If you use automated tools (like Burp Suite Active Scan), you must strictly rate-limit your requests to avoid degrading our service. Volumetric/DoS attacks will result in immediate removal from the program.\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g. Stack Traces, application or server errors).\u003c/li\u003e\n\u003cli\u003eFingerprinting / banner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eLogout Cross-Site Request Forgery (logout CSRF).\u003c/li\u003e\n\u003cli\u003eReflected Text Injection / Non-Persistent Content Spoofing (modifying text on a page via a URL parameter without XSS or persistent database changes).\u003c/li\u003e\n\u003cli\u003ePresence of application or web browser ‘autocomplete’ or ‘save password’ functionality.\u003c/li\u003e\n\u003cli\u003eLack of Secure/HTTPOnly flags on non-sensitive Cookies.\u003c/li\u003e\n\u003cli\u003eLack of Security Speedbump when leaving the site.\u003c/li\u003e\n\u003cli\u003eWeak Captcha / Captcha Bypass.\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force and account lockout not enforced.\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration.\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers, specifically (\u003ca href=\"https://owasp.org/www-project-secure-headers/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://owasp.org/www-project-secure-headers/\u003c/a\u003e), e.g.\n\n\u003cul\u003e\n\u003cli\u003eStrict-Transport-Security.\u003c/li\u003e\n\u003cli\u003eX-Frame-Options.\u003c/li\u003e\n\u003cli\u003eX-XSS-Protection.\u003c/li\u003e\n\u003cli\u003eX-Content-Type-Options.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy, X-Content-Security-Policy, X-WebKit-CSP.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy-Report-Only.\u003c/li\u003e\n\u003cli\u003eCache-Control and Pragma\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eHTTP/DNS cache poisoning.\u003c/li\u003e\n\u003cli\u003eSSL/TLS Issues, e.g.\n\n\u003cul\u003e\n\u003cli\u003eSSL Attacks such as BEAST, BREACH, Renegotiation attack.\u003c/li\u003e\n\u003cli\u003eSSL Forward secrecy not enabled.\u003c/li\u003e\n\u003cli\u003eSSL weak/insecure cipher suites.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSelf-XSS reports will not be accepted.\n\n\u003cul\u003e\n\u003cli\u003eSimilarly, any XSS where local access is required (i.e. User-Agent Header injection) will not be accepted. The only exception will be if you can show a working off-path MiTM attack that will allow for the XSS to trigger.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerabilities that are limited to unsupported browsers will not be accepted (i.e. \"this exploit only works in IE6/IE7\"). A list of supported browsers can be found \u003ca href=\"https://support.atlassian.com/atlassian-account/docs/supported-browsers-for-atlassian-cloud-products/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eKnown vulnerabilities in used libraries, or the reports that an Atlassian product uses an outdated third party library (e.g. jQuery, Apache HttpComponents etc) unless you can prove exploitability.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect SPF records of any kind.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect DMARC records of any kind.\u003c/li\u003e\n\u003cli\u003eSource code disclosure vulnerabilities.\u003c/li\u003e\n\u003cli\u003eInformation disclosure of non-confidential information (e. g. issue id, project id, commit hashes).\u003c/li\u003e\n\u003cli\u003eThe ability to upload/download viruses or malicious files to the platform.\u003c/li\u003e\n\u003cli\u003eEmail bombing/Flooding/rate limiting.\u003c/li\u003e\n\u003cli\u003eJWT in ajax requests ignores path and HTTP method.\u003c/li\u003e\n\u003cli\u003eFor some of our apps, we allow arbitrary HTML templates to be defined by administrators. Those could potentially be used for XSS attacks, however since only administrators have access we don't consider those as security threats.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou must ensure that customer data is not affected in any way as a result of your testing. Please ensure you're being non-destructive whilst testing and are only testing on instances that you own.\u003c/li\u003e\n\u003cli\u003eIn addition to above, customer instances are not to be accessed in any way (i.e. no customer data is accessed, customer credentials are not to be used or \"verified\")\u003c/li\u003e\n\u003cli\u003eIf you believe you have found sensitive customer data (e.g., login credentials, API keys etc) or a way to access customer data (i.e. through a vulnerability) report it, but do not attempt to successfully validate if/that it works.\u003c/li\u003e\n\u003cli\u003eSeveral similar reports which have the same root cause or can be resolved with the same bugfix will be counted as duplicates,\u003c/li\u003e\n\u003cli\u003eReports need to be submitted in plain text (associated pictures/videos are fine as long as they're in standard formats). Non-plain text reports (e.g. PDF, DOCX) will be asked to be resubmitted in plain text.\u003c/li\u003e\n\u003cli\u003eGrants/awards are at the discretion of Requirement Yogi and we withhold the right to grant, modify or deny grants. But we'll be fair about it.\u003c/li\u003e\n\u003cli\u003eTax implications of any payouts are the sole responsibility of the reporter.\u003c/li\u003e\n\u003cli\u003eDo NOT conduct non-technical attacks such as social engineering, phishing or unauthorized access to infrastructure.\u003c/li\u003e\n\u003cli\u003eDo NOT test the physical security of Requirement Yogi offices, employees, equipment, etc.\u003c/li\u003e\n\u003cli\u003eThis bounty follows Bugcrowd’s standard disclosure terms.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003ePublic Disclosure\u003c/h3\u003e\n\n\u003cp\u003eBefore disclosing an issue publicly we require that you first obtain consent from us. Requirement Yogi will process requests for public disclosure on a per report basis. Requests to publicly disclose an issue that has not yet been fixed for customers will be rejected. Any researcher found publicly disclosing reported vulnerabilities without Requirement Yogi's written consent will have any allocated bounty withdrawn and disqualified from the program.\u003c/p\u003e\n\n\u003ch3\u003eSafe Harbor\u003c/h3\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls used strictly during and for the purpose of your good-faith security testing;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms of Service that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\nYou are expected, as always, to comply with all applicable laws.\nIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThank you very much for your hard work.\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"be3928bd-4aa5-45a2-a6d1-0fa69816e17a","name":"In Scope","targets":[{"id":"bf4b38df-8b36-4424-87f6-0bebc94ecc86","uri":"https://marketplace.atlassian.com/apps/1214094/requirement-yogi-for-jira?hosting=cloud","name":"Requirement Yogi for Jira Cloud - https://marketplace.atlassian.com/apps/1214094/requirement-yogi-for-jira?hosting=cloud","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"9d30859a-7b99-4e0e-ba7e-1c8fe052a662","sortOrder":0},"sortOrder":0,"tags":[{"id":"29b28ccd-4801-41ae-803f-74d103419965","name":"Jira","targetId":"bf4b38df-8b36-4424-87f6-0bebc94ecc86"},{"id":"69f9dcc7-e598-4efc-be48-7c36a7689651","name":"Atlassian Forge","targetId":"bf4b38df-8b36-4424-87f6-0bebc94ecc86"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"bf4b38df-8b36-4424-87f6-0bebc94ecc86"}],"recentChangeFlags":null},{"id":"d0837a8a-ea06-4772-953d-e784d516c09a","uri":"https://app.requirementyogi.com","name":"Standalone app (HTML assets)","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"10d9d13b-115c-4ba3-a24b-2ee86b43ff7c","sortOrder":2},"sortOrder":2,"tags":[{"id":"3ff3fda3-da69-45cc-9640-b57d3228af94","name":"OAuth","targetId":"d0837a8a-ea06-4772-953d-e784d516c09a"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d0837a8a-ea06-4772-953d-e784d516c09a"}],"recentChangeFlags":null},{"id":"a4e20cee-3123-449a-aea2-b67508c98454","uri":"https://api.requirementyogi.com","name":"REST API","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e7dae417-c3d6-4f67-b1ae-ea2768ca885a","sortOrder":3},"sortOrder":3,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"a4e20cee-3123-449a-aea2-b67508c98454"}],"recentChangeFlags":null},{"id":"b4b51020-8cc3-4192-b95e-eb134d787b4b","uri":"https://auth.requirementyogi.com","name":"Keycloak","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e7dbbddb-1b65-4c79-b203-5fc3ef424ed0","sortOrder":4},"sortOrder":4,"tags":[{"id":"59cdb1e5-8e65-4040-b1eb-c323dfee5a53","name":"Authentication Systems","targetId":"b4b51020-8cc3-4192-b95e-eb134d787b4b"}],"recentChangeFlags":null},{"id":"cbd44f7d-c127-4c0b-93ec-f300078b6f2a","uri":"https://confluence.requirementyogi.com","name":"Confluence app back-end","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"71b553ea-24c2-42e5-8a61-466474dd470a","sortOrder":5},"sortOrder":5,"tags":[{"id":"69f9dcc7-e598-4efc-be48-7c36a7689651","name":"Atlassian Forge","targetId":"cbd44f7d-c127-4c0b-93ec-f300078b6f2a"}],"recentChangeFlags":null},{"id":"51163fe8-cd0d-416a-b5bc-eb83be7da734","uri":"https://jira.requirementyogi.com","name":"Jira app back-end","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d0433292-e29d-4c6c-8aa3-9ea591a64600","sortOrder":6},"sortOrder":6,"tags":[{"id":"69f9dcc7-e598-4efc-be48-7c36a7689651","name":"Atlassian Forge","targetId":"51163fe8-cd0d-416a-b5bc-eb83be7da734"}],"recentChangeFlags":null},{"id":"319ebc3f-8d93-4a90-8754-42027f7a9cf0","uri":"https://marketplace.atlassian.com/apps/1212523/requirements-yogi?hosting=cloud","name":"Requirement Yogi for Confluence Cloud - https://marketplace.atlassian.com/apps/1212523/requirements-yogi?hosting=cloud","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"3768d61b-1d8a-4fd3-ae10-7463e970a065","sortOrder":6},"sortOrder":6,"tags":[{"id":"69f9dcc7-e598-4efc-be48-7c36a7689651","name":"Atlassian Forge","targetId":"319ebc3f-8d93-4a90-8754-42027f7a9cf0"},{"id":"85756483-8cbd-4a28-8ec2-e4c59a7981fe","name":"Confluence","targetId":"319ebc3f-8d93-4a90-8754-42027f7a9cf0"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"319ebc3f-8d93-4a90-8754-42027f7a9cf0"}],"recentChangeFlags":null},{"id":"e9caf865-6e94-433b-a52b-7590bce31edc","uri":"https://ww1.requirementyogi.cloud","name":"Old back-end for Confluence app","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5b0a1885-e300-472c-adff-9ea81a6e8c54","sortOrder":7},"sortOrder":7,"tags":null,"recentChangeFlags":null},{"id":"b317672a-bd0b-40ed-a5a9-dc33bb781f10","uri":"https://ww2.requirementyogi.cloud","name":"Old back-end for Jira app","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a1fe351f-cff4-4fce-9df3-7b1ab1ad0502","sortOrder":8},"sortOrder":8,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"e9512833-6319-4136-a8b6-a7ae1ee49dba","p1MaxCents":150000,"p1MinCents":150000,"p2MaxCents":90000,"p2MinCents":90000,"p3MaxCents":30000,"p3MinCents":30000,"p4MaxCents":10000,"p4MinCents":10000,"p5MaxCents":10000,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":1500,"max":1500},"2":{"min":900,"max":900},"3":{"min":300,"max":300},"4":{"min":100,"max":100},"5":{"min":0,"max":100}},"recentChangeFlags":null},{"id":"0fa68a4c-d2b3-4d57-a5d0-de698d235512","name":"Out of scope","targets":[{"id":"1005aa45-ba80-4a41-971b-376fbd5ce970","uri":"https://docs.requirementyogi.com","name":"Documentation (Out of scope)","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a991ca46-43c0-4e7e-94f8-aaa8f50efb03","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"1005aa45-ba80-4a41-971b-376fbd5ce970"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"13417475-b7ef-44cd-b210-c3f8f316ed7d","code":"requirement-yogi","state":"in_progress","endsAt":null,"bountyId":"c5d3af39-9fef-4428-b894-cd14d4ad86fb","startsAt":"2020-09-22T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/a840/8680/067d07aa/8d7aa11ffbcdfa96f660bec4efa71b87_playsql.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2020-09-22T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/requirement-yogi","changelogs":"/engagements/requirement-yogi/changelog","submissions":null,"announcements":"/engagements/requirement-yogi/announcements","hallOfFame":"/engagements/requirement-yogi/hall_of_fames","crowdstream":"/engagements/requirement-yogi/crowdstream"},"announcementsCount":3,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/requirement-yogi/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=requirement-yogi\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/requirement-yogi/engagement_subscribers","engagementChangelogsUrl":"/engagements/requirement-yogi/changelog","publishedAt":"2026-06-24T23:40:19.459Z","engagementChangelogUrl":"/engagements/requirement-yogi/changelog/1a2d4655-56f5-4c58-a543-cd511c1ddb7c","createUserFeedbacksUrl":"/engagements/requirement-yogi/feedbacks","engagementCrowdstreamUrl":"/engagements/requirement-yogi/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}