{"id":"4a9ba772-b58c-4648-9640-828df28f631f","engagementId":"dfb0df83-ec29-428e-a143-e848316467c6","data":{"brief":{"id":"fa00ad35-e129-4a24-b65b-65a3e69484c0","name":"U.S. Small Business Administration (SBA) Vulnerability Disclosure Program","tagline":"SBA works to ignite change and spark action so small businesses can confidently start, grow, expand, or recover.","description":"\u003ch2\u003ePolicy\u003c/h2\u003e\n\n\u003cp\u003eThe U.S. Small Business Administration (SBA) takes seriously our responsibility to protect the public’s information, including financial and personal information, from unwarranted disclosure. However, as an agency with extensive citizen-facing data collection requirements, the risk of disclosure is real.\u003c/p\u003e\n\n\u003cp\u003eTo help minimize that risk, and in accordance with the U.S. Department of Homeland Security (DHS) Binding Operational Directives (BODs), SBA encourages cybersecurity researchers to report vulnerabilities that they have discovered so that SBA can take appropriate action to fix those vulnerabilities and keep our stakeholders’ information safe.\u003c/p\u003e","industryTagId":"2a38890b-c88e-4bc0-8db0-02059f3fafe6","targetsOverview":"\u003ch2\u003eScope\u003c/h2\u003e\n\n\u003cp\u003eAny services not expressly listed above, such as any connected services, are excluded from scope and are not authorized for testing. Vulnerabilities found in non-federal systems from our vendors fall outside of this policy’s scope and should be reported directly to the vendor according to their disclosure policy (if any). If cybersecurity researchers are not sure whether a system or endpoint is in scope or not, contact CISO@sba.gov before starting research.\u003c/p\u003e\n\n\u003cp\u003eIf the cybersecurity researcher encounters any of the below on our systems while testing within the scope of this policy, stop the test and notify us immediately:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePersonally Identifiable Information (PII)\u003c/li\u003e\n\u003cli\u003eFinancial information (e.g., credit card or bank account numbers)\u003c/li\u003e\n\u003cli\u003eProprietary information or trade secrets of any party\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cp\u003eThe following test types are not authorized:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eUser interface bugs or typos\u003c/li\u003e\n\u003cli\u003eNetwork denial of service (DoS or DDoS) tests\u003c/li\u003e\n\u003cli\u003ePhysical access testing (office access, open doors, tailgating)\u003c/li\u003e\n\u003cli\u003eSocial engineering such as phishing or any other non-technical vulnerability testing\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eGuidelines\u003c/h2\u003e\n\n\u003cp\u003eWe ask that cybersecurity researchers:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eMake every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data\u003c/li\u003e\n\u003cli\u003eOnly use exploits to the extent necessary to confirm a vulnerability. This includes not using an exploit to compromise or exfiltrate data, establish command line access and/or persistence, or use the exploit to “pivot” to other systems.\u003c/li\u003e\n\u003cli\u003eOnce it is confirmed that a vulnerability exists or gaining access to any of the sensitive data outlined below, stop the test, and notify us immediately.\u003c/li\u003e\n\u003cli\u003eKeep confidential any information about discovered vulnerabilities \u003cstrong\u003euntil given explicit and written permission by SBA to disclose the information about the discovered vulnerabilities\u003c/strong\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eReports should include the following details:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDescription of the location and potential impact of the vulnerability\u003c/li\u003e\n\u003cli\u003eDate and time that the vulnerability test was executed\u003c/li\u003e\n\u003cli\u003eA detailed description of the steps required to reproduce the vulnerability. Proof of concept scripts, screenshots, and screen captures are all helpful. Please use extreme care to properly label and protect any exploit code.\u003c/li\u003e\n\u003cli\u003eAny technical information and related materials needed to reproduce the issue\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAfter review, SBA may share some vulnerability data with the other federal agencies, as well as any affected vendors or open source projects.\u003c/p\u003e\n\n\u003ch2\u003eAuthorization\u003c/h2\u003e\n\n\u003cp\u003eSBA will not pursue civil action for accidental, good faith violations of its policy or initiate a complaint to law enforcement for unintentional violations. SBA considers activities conducted consistent with the policy to constitute “authorized” conduct under the Computer Fraud and Abuse Act. If legal action is initiated by a third party against a party who complied with the vulnerability disclosure policy, SBA will take steps to make it known, either to the public or to the court, that the individual’s actions were conducted in compliance with the policy.\u003c/p\u003e\n\n\u003cp\u003eDisclosure of vulnerabilities is voluntary. In no case shall disclosure of vulnerability information to the SBA constitute a contractual or any other type of relationship with SBA. By submitting a vulnerability, the cybersecurity researcher must expressly acknowledge that, “I have no expectation of payment for these services and I expressly waive any future pay claims against the U.S. government related to the submission.”\u003c/p\u003e\n\n\u003ch2\u003eCoordinated disclosure\u003c/h2\u003e\n\n\u003cp\u003eSBA is committed to continually remediating vulnerabilities and disclosing the details of those vulnerabilities when fixes are implemented. SBA further believes that public disclosure of vulnerabilities is an essential part of the vulnerability disclosure process, and that one of the best ways to make software and applications better is to share such remediations.\u003c/p\u003e\n\n\u003cp\u003eHowever, disclosure of a vulnerability in the absence of a timely remediation increases risk to our stakeholders’ data, and so we ask cybersecurity researchers to refrain from sharing SBA’s vulnerability information with others while we work on our remediation approach.  If others should be informed of the vulnerability before the appropriate remediation is available, please let us know so we can coordinate.\u003c/p\u003e\n\n\u003cp\u003eSBA may want to coordinate a public notification with a cybersecurity researcher to be published simultaneously with the remediation, but cybersecurity researchers may self-disclose if they prefer.\u003c/p\u003e\n\n\u003cp\u003eSBA does not publish information about a cybersecurity researcher without his/her permission. In some cases, SBA may have sensitive information that must be redacted from public disclosure, so cybersecurity researchers must obtain approval from SBA before self-disclosing. Failing to do so undermines the good faith sentiment that this policy strives to achieve.\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"7fddfdb2-86e5-4df3-b6a6-5230260a7a57","name":"In Scope Targets","targets":[{"id":"a5633fc4-935e-44ca-9fff-eb580cf4806d","uri":"https://www.sba.gov","name":"*.sba.gov","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"45df4fa6-cb1f-4908-9a1e-f96fc8e308c9","sortOrder":0},"sortOrder":0,"tags":[{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"a5633fc4-935e-44ca-9fff-eb580cf4806d"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"a5633fc4-935e-44ca-9fff-eb580cf4806d"},{"id":"9dd4899d-3a63-4126-8c83-c1fc1de50c25","name":"Amazon Cloudfront","targetId":"a5633fc4-935e-44ca-9fff-eb580cf4806d"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"a5633fc4-935e-44ca-9fff-eb580cf4806d"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"a5633fc4-935e-44ca-9fff-eb580cf4806d"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a5633fc4-935e-44ca-9fff-eb580cf4806d"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"a5633fc4-935e-44ca-9fff-eb580cf4806d"}],"recentChangeFlags":null},{"id":"0391c193-86b6-4928-826f-62952fe345f4","uri":"https://www.sbir.gov/","name":"*.sbir.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"fe01eddd-bf39-4453-b2f9-646ed492b9f6","sortOrder":1},"sortOrder":1,"tags":[{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"0391c193-86b6-4928-826f-62952fe345f4"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"0391c193-86b6-4928-826f-62952fe345f4"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"0391c193-86b6-4928-826f-62952fe345f4"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"0391c193-86b6-4928-826f-62952fe345f4"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"0391c193-86b6-4928-826f-62952fe345f4"}],"recentChangeFlags":null},{"id":"2a8fc46b-7fad-47c5-a797-ef9cd0d67083","uri":"https://www.nwbc.gov/","name":"*.nwbc.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"71bbbe9e-5106-4b6a-a15d-b7439cd3e743","sortOrder":2},"sortOrder":2,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"2a8fc46b-7fad-47c5-a797-ef9cd0d67083"},{"id":"487e9af0-2610-4813-a092-ea46f4cb6de1","name":"Wordpress","targetId":"2a8fc46b-7fad-47c5-a797-ef9cd0d67083"},{"id":"5644ab16-c7ca-4ff7-ac95-383343dab77f","name":"MySQL","targetId":"2a8fc46b-7fad-47c5-a797-ef9cd0d67083"},{"id":"9dd4899d-3a63-4126-8c83-c1fc1de50c25","name":"Amazon Cloudfront","targetId":"2a8fc46b-7fad-47c5-a797-ef9cd0d67083"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"2a8fc46b-7fad-47c5-a797-ef9cd0d67083"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"2a8fc46b-7fad-47c5-a797-ef9cd0d67083"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2a8fc46b-7fad-47c5-a797-ef9cd0d67083"}],"recentChangeFlags":null},{"id":"c554ce3c-86de-43d1-9f93-5727bcf7f08e","uri":"https://business.gov","name":"*.business.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8ba59481-a4d5-4317-aced-6bd008f98747","sortOrder":3},"sortOrder":3,"tags":[{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"c554ce3c-86de-43d1-9f93-5727bcf7f08e"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"c554ce3c-86de-43d1-9f93-5727bcf7f08e"},{"id":"9dd4899d-3a63-4126-8c83-c1fc1de50c25","name":"Amazon Cloudfront","targetId":"c554ce3c-86de-43d1-9f93-5727bcf7f08e"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"c554ce3c-86de-43d1-9f93-5727bcf7f08e"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"c554ce3c-86de-43d1-9f93-5727bcf7f08e"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"c554ce3c-86de-43d1-9f93-5727bcf7f08e"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003ePlease note: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ehttps://www.business.gov does redirect to https://www.sba.gov, however it is included within scope to ensure we capture all targets. \u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"dfb0df83-ec29-428e-a143-e848316467c6","code":"sba-vdp","state":"in_progress","endsAt":null,"bountyId":"59b666f7-f0e8-4c9b-be45-a3404bf43491","startsAt":"2025-01-28T17:12:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Government","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/1c3f/a353/d55517f2/2d6a5bae0baa76069055689f228d54d5_1631368242659.jpeg","logoBackgroundColor":"#fcfffc","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-01-28T18:00:00.991Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/sba-vdp","changelogs":"/engagements/sba-vdp/changelog","submissions":null,"announcements":"/engagements/sba-vdp/announcements","hallOfFame":"/engagements/sba-vdp/hall_of_fames","crowdstream":"/engagements/sba-vdp/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/sba-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=sba-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/sba-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/sba-vdp/changelog","publishedAt":"2025-01-28T18:00:01.319Z","engagementChangelogUrl":"/engagements/sba-vdp/changelog/4a9ba772-b58c-4648-9640-828df28f631f","createUserFeedbacksUrl":"/engagements/sba-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/sba-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}