{"id":"3f4cffdb-b7b7-49e5-ab22-4038907649f1","engagementId":"e28b5f44-30b0-41c5-8792-b91ffd924653","data":{"brief":{"id":"6d2a2505-c768-4d94-8300-a84dde577f56","name":"Sonic Healthcare Vulnerability Disclosure Engagement","tagline":"Sonic Healthcare is an internationally renowned healthcare provider with specialist operations in laboratory medicine / pathology, radiology, general practice medicine and corporate medical services.   If you believe you have found a potential security vulnerability within a public asset Sonic Healthcare and its subsidiaries, please share your findings.","description":"\u003cp\u003e\u003cstrong\u003eAbout this policy\u003c/strong\u003e\u003cbr\u003e\nThe Sonic Healthcare vulnerability disclosure policy gives security researchers a point of contact to directly submit their research findings if they believe they have found a potential security vulnerability within an asset of the Sonic Healthcare company and its subsidiaries.\u003c/p\u003e\n\n\u003cp\u003eWe have endeavoured to keep the security of our systems a priority but understand there may still be vulnerabilities.\u003c/p\u003e\n\n\u003cp\u003eAs such, we encourage engagement with the security community. This policy allows security researchers to share their findings with us. If you think you have found a potential vulnerability in one of our applications, services or products, please contact us as soon as possible.\u003c/p\u003e\n\n\u003cp\u003ePlease note, there may not necessarily be compensation for finding potential or confirmed vulnerabilities. Any potential reward will reflect our perceived risk of the disclosed vulnerability.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eGuidelines :\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e Please be mindful that some forms trigger messages to staff; please be considerate of 'spam'. Examples include excessive sign-ups to products or contacting Sonic Healthcare customer support.\u003c/li\u003e\n\u003cli\u003eRefrain from intentionally deleting production data\u003c/li\u003e\n\u003cli\u003eRefrain from excessive denial-of-service attacks or stress testing\u003c/li\u003e\n\u003cli\u003eEnough detail should be included so that your steps may be reproduced. Only go as far as necessary to demonstrate your proof-of-concept for the vulnerability.\u003c/li\u003e\n\u003cli\u003eRefrain from active exploitation of the vulnerability. This includes exfiltration or downloading of company data, disclosure of confidential information, and/or disrupting our customers’ experience.\u003c/li\u003e\n\u003cli\u003eAny vulnerability reported under this policy must be kept confidential. Please do not publicly release your research until we have had the opportunity to finish investigating and fixing or mitigating the vulnerability.\u003c/li\u003e\n\u003cli\u003eWe strongly recommend that researchers include a custom HTTP header containing their Bugcrowd username, for example: X-Bugcrowd: \u0026lt;username\u0026gt;\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"50214b57-2dde-40fd-ae5a-6680372523d4","targetsOverview":"\u003cp\u003e\u003cstrong\u003eScope\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eAny product, service, IP or domain wholly owned by Sonic Healthcare on the public internet\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eThis policy does not cover:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eDuplicate or known vulnerabilities\u003cbr\u003e\nTargeted social engineering of our patients, doctors or staff\u003cbr\u003e\nWeak or insecure SSL ciphers and certificates\u003cbr\u003e\nPhysical attacks\u003cbr\u003e\nModifications to GitHub wiki pages\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"62ea47ac-44b9-4641-b103-0c9d5cae71bb","name":"In Scope","targets":[{"id":"9e423b2d-0c51-4e05-86e0-968eac45dc95","uri":"","name":"Any internet-exposed assets that belong to Sonic Healthcare company and its subsidiaries","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"596d0db5-03c7-4f08-9000-22871472bb8e","sortOrder":0},"sortOrder":0,"tags":[{"id":"eaa69542-87cd-413a-9b74-3e75f9fb01e4","name":"Angular","targetId":"9e423b2d-0c51-4e05-86e0-968eac45dc95"},{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"9e423b2d-0c51-4e05-86e0-968eac45dc95"},{"id":"803518dc-5ae1-4e48-8de4-5b61b42a6bd0","name":"Amazon S3","targetId":"9e423b2d-0c51-4e05-86e0-968eac45dc95"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9e423b2d-0c51-4e05-86e0-968eac45dc95"}],"recentChangeFlags":null},{"id":"0dd99fa3-17fe-4d38-a2f2-403a5931f1ba","uri":"","name":"Other","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1b10943c-fc62-4b6d-a07b-095ca305960a","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"e28b5f44-30b0-41c5-8792-b91ffd924653","code":"sonic-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"bdfd3e01-6333-4087-bd8b-75f28561e2ed","startsAt":"2025-08-26T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Healthcare","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/6b77/9383/baf19d86/287d862ef6e70a7cf2ea921703304e47_SonicHealthcareLogo.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-08-26T18:00:00.879Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/sonic-vdp-pro","changelogs":"/engagements/sonic-vdp-pro/changelog","submissions":null,"announcements":"/engagements/sonic-vdp-pro/announcements","hallOfFame":"/engagements/sonic-vdp-pro/hall_of_fames","crowdstream":"/engagements/sonic-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/sonic-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=sonic-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/sonic-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/sonic-vdp-pro/changelog","publishedAt":"2026-09-02T05:14:07.179Z","engagementChangelogUrl":"/engagements/sonic-vdp-pro/changelog/3f4cffdb-b7b7-49e5-ab22-4038907649f1","createUserFeedbacksUrl":"/engagements/sonic-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/sonic-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}