{"id":"67774d34-82ea-4d04-bfdf-89141a724bbb","engagementId":"b95fbd1c-4733-449d-add6-436f1a8db845","data":{"brief":{"id":"8838d159-3cbf-4d62-9adb-249b4021b966","name":"Statuspage","tagline":"Hosted status pages for SaaS, infrastructure, and API-based companies","description":"\u003cp\u003eStatuspage launched in 2013 to give companies a better way to be more transparent with their customers. We recognize managing a status page outside of one’s own infrastructure can be a hassle, and hope to increase the transparency of the web by making it easier to do so.\u003c/p\u003e\n\n\u003cp\u003eBefore you begin, please read and understand the \u003ca href=\"https://bugcrowd.com/resources/standard-disclosure-terms\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eStandard Disclosure Terms\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eBelow is a list of some of the vulnerability classes that we are seeking reports for:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eServer-side Remote Code Execution (RCE)\u003c/li\u003e\n\u003cli\u003eServer-Side Request Forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eStored/Reflected Cross-site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eCross-site Request Forgery (CSRF)\u003c/li\u003e\n\u003cli\u003eSQL Injection (SQLi)\u003c/li\u003e\n\u003cli\u003eXML External Entity Attacks (XXE)\u003c/li\u003e\n\u003cli\u003eAccess Control Vulnerabilities (Insecure Direct Object Reference issues, etc)\u003c/li\u003e\n\u003cli\u003ePath/Directory Traversal Issues\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eEnsure you review the out of scope and exclusions list for further details.\u003c/p\u003e\n\n\u003ch2\u003eAccessing Statuspage\u003c/h2\u003e\n\n\u003cp\u003ePlease visit \u003ca href=\"https://manage.statuspage.io/security-researcher\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://manage.statuspage.io/security-researcher\u003c/a\u003e to identify yourself as a security researcher, this will give you a free account for a month. You'll need to create an account and log in to view this page. \u003c/p\u003e\n\n\u003ch2\u003eDisclosure Request Guidance\u003c/h2\u003e\n\n\u003cp\u003eSubmissions that meet the following requirements will be considered for disclosure upon request:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe submission has been accepted\u003c/li\u003e\n\u003cli\u003eThe reported vulnerability has been fixed and released in production\u003c/li\u003e\n\u003cli\u003eThe submission does not regard a customer instance or a customer’s account \u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003e\u003cem\u003ePlease read the note on XSS at the bottom of this bounty brief.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eAny domain/property not listed in the targets section is strictly out of scope (for more information please see the out of scope and exclusions sections below).\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eSome third party hosts are also in scope. Any third party host will only qualify if the attack can exploit our customers directly. These third parties include:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ehelp.statuspage.io\u003c/li\u003e\n\u003cli\u003edoers.statuspage.io\u003c/li\u003e\n\u003cli\u003efilepicker.io\u003c/li\u003e\n\u003cli\u003esegment.io\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cp\u003eAnything not declared as a target or in scope above should be considered out of scope for the purposes of this bug bounty. However for verbosity and to help avoid grey areas, below are examples of what is considered out of scope.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe following targets are out of scope:\n\n\u003cul\u003e\n\u003cli\u003ewww.statuspage.io\u003c/li\u003e\n\u003cli\u003emetastatuspage.com\u003c/li\u003e\n\u003cli\u003eblog.statuspage.io\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAny widely-disclosed vulnerabilities in any public vendor components. For example Heartbleed or CCS affecting Amazon ELB.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eThe following finding types are specifically excluded from the bounty\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe use of Automated scanners is strictly prohibited (we have these tools too - don't even think about using them)\u003c/li\u003e\n\u003cli\u003eNo Load testing (DoS/DDoS etc) is allowed on the instance.\n\n\u003cul\u003e\n\u003cli\u003eThis includes application DoS as well as network DoS.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSelf-XSS reports will not be accepted.\n\n\u003cul\u003e\n\u003cli\u003eSimilarly, any XSS where local access is required (i.e. User-Agent Header injection) will not be accepted. The only exception will be if you can show a working off-path MiTM attack that will allow for the XSS to trigger.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerabilities that are limited to unsupported browsers will not be accepted (i.e. \"this exploit only works in IE6/IE7\"). A list of supported browsers can be found \u003ca href=\"https://confluence.atlassian.com/display/Cloud/Supported+browsers\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eKnown vulnerabilities in used libraries, or the reports that a Statuspage product uses an outdated third party library (e.g. jQuery, Apache HttpComponents etc) unless you can prove exploitability.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect SPF records of any kind.\u003c/li\u003e\n\u003cli\u003eSource code disclosure vulnerabilities.\u003c/li\u003e\n\u003cli\u003eInformation disclosure of non-confidential information (e. g. issue id, project id, commit hashes).\u003c/li\u003e\n\u003cli\u003eThe ability to upload/download viruses or malicious files to the platform.\u003c/li\u003e\n\u003cli\u003ePassword strength requirements\u003c/li\u003e\n\u003cli\u003eEmail bombing/Flooding/rate limiting\u003c/li\u003e\n\u003cli\u003eHTML injection. This is a feature of Statuspage templates, and is supported by the product. The exception is if the HTML injection leads to an XSS (other than self-xss). Then it is deemed in scope (see the section below about XSS for more details).\u003c/li\u003e\n\u003cli\u003eCSV Injection\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe bug does not depend on any part of the Statuspage product being in a particular 3rd-party environment. In particular, we are not responsible for vulnerabilities on the sites of any of our customers that may happen to use Statuspage, unless those vulnerabilities might affect other Statuspage users or our main site.\u003c/li\u003e\n\u003cli\u003eThe bug is an application vulnerability (database injection, public status page XSS, privilege escalation, session hijacking, remote code execution and so forth) in our main website, the JavaScript widget, our API, any customer status page, or one of our other core services.\u003c/li\u003e\n\u003cli\u003eThe bug cannot require extended user action to execute. For example, stored XSS must be present on a public status page, and cannot require user responding to a team member account invitation and then subsequently logging in to view the stored XSS page.\u003c/li\u003e\n\u003cli\u003eThe bug's effects are not limited only to browser/version combinations that cannot be conceivably called modern in any way -- we're looking at you, IE6/7.\u003c/li\u003e\n\u003cli\u003eYou are the original source of the bug through your own research, and you are the first person to report the particular vulnerability to us.\u003c/li\u003e\n\u003cli\u003eYou're not a minor, nor are you on any list of people we are not legally allowed to do business with.\u003c/li\u003e\n\u003cli\u003eYou must ensure that customer data is not affected in any way as a result of your testing. Please ensure you're being non-destructive whilst testing.\u003c/li\u003e\n\u003cli\u003eIn addition to above, customer instances are not to be accessed in any way (i.e. no customer data is accessed, customer credentials are not to be used or \"verified\")\n\n\u003cul\u003e\n\u003cli\u003eIf you believe you have found sensitive customer data (e.g., login credentials, API keys etc) or a way to access customer data (i.e. through a vulnerability) report it, but do not attempt to successfully validate if/that it works.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cem\u003eUse of any automated tools/scanners is strictly prohibited\u003c/em\u003e and will lead to you being removed from the program (trust us, we have those tools too).\u003c/li\u003e\n\u003cli\u003eReports need to be submitted in plain text (associated pictures/videos are fine as long as they're in standard formats). Non-plain text reports (e.g. PDF, DOCX) will be asked to be resubmitted in plain text.\u003c/li\u003e\n\u003cli\u003eSufficiently similar access control issues should be grouped in one report. Atlassian defines “sufficiently similar” as issues that use the same configuration for bypassing a particular control, which may be used on multiple related vulnerable endpoints or actions (User X can Create/Delete/Edit Resource Y).\u003c/li\u003e\n\u003cli\u003eGrants/awards are at the discretion of Statuspage and we withhold the right to grant, modify or deny grants. But we'll be fair about it.\u003c/li\u003e\n\u003cli\u003eTax implications of any payouts are the sole responsibility of the reporter.\u003c/li\u003e\n\u003cli\u003eDo NOT conduct non-technical attacks such as social engineering, phishing or unauthorized access to infrastructure.\u003c/li\u003e\n\u003cli\u003eDo NOT test the physical security of Statuspage offices, employees, equipment, etc.\u003c/li\u003e\n\u003cli\u003ePlease do not test our capacity, or for Denial of Service or similar exploits.\u003c/li\u003e\n\u003cli\u003ePlease do all testing on your own account, and do not impact our customers in any way.\u003c/li\u003e\n\u003cli\u003eStored XSS attacks must be viewable on a publicly hosted page residing on a *.statuspage.io subdomain. Any stored XSS attack that requires a user to sign up for an account as a team member, or appear on a CNAME domain, are not eligible for a reward or recognition.\n\n\u003cul\u003e\n\u003cli\u003eStored XSS as it relates to custom header/footer HTML will behave differently on a live status page. While pages are private, stored XSS is allowed for page setup purposes. See http://bitbucket.statuspage.io(CSS only) vs http://status.bitbucket.org (CSS \u0026amp; HTML) for a live example.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThis program adheres to the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e for the prioritization of findings. However, Statuspage reserves the right to downgrade or upgrade a report's findings based on the criticality and impact of the report.\u003c/p\u003e\n\n\u003ch3\u003eReporting Guidelines\u003c/h3\u003e\n\n\u003cp\u003eWhere applicable, please include the following information. This will greatly assist in the triage, validation, and acceptance processes and will result in more clear security risk communication and timely report acceptances.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eBrief summary (please include product versions affected/tested)\u003c/li\u003e\n\u003cli\u003ePrerequisites (including any products, user privileges, tools required, files prepared, web server configurations, or any other initial conditions to prior to initiating the proof of concept)\u003c/li\u003e\n\u003cli\u003eReproduction steps including vulnerable endpoints, parameters, payloads used, source of any scripts used, or command line inputs (burp requests, screenshots and recordings are \u003cstrong\u003ehighly\u003c/strong\u003e encouraged)\u003c/li\u003e\n\u003cli\u003eExpected results/behavior vs actual results/behavior (include any formal documentation, resources, or links that state the expected behavior)\u003c/li\u003e\n\u003cli\u003eAssessed security impact (as it relates to the Confidentiality, Integrity, and/or Availability of the product)\u003c/li\u003e\n\u003cli\u003ePossible mitigations, fixes, or security controls\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003ePublic Disclosure\u003c/h2\u003e\n\n\u003cp\u003eAt Atlassian, one of our values is Open Company, No Bullshit, we believe that vulnerability disclosure is a part of that value. We hold ourselves to the security bug fix service level objectives, found \u003ca href=\"https://www.atlassian.com/trust/security/bug-fix-policy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e, and will accept disclosure requests in the bug bounty program after the issue has been fixed and released in production. However, if the report contains any information regarding a customer instance or data the request will be rejected. If you are planning to disclose outside of the bug bounty, we ask that you give us reasonable notice and wait until the \u003ca href=\"https://www.atlassian.com/trust/security/bug-fix-policy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eassociated SLO\u003c/a\u003e has passed.  \u003c/p\u003e\n\n\u003ch3\u003eSafe Harbor\u003c/h3\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYou are expected, as always, to comply with all applicable laws.\u003cbr\u003e\nIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"40d4f888-8280-4ad3-bd9b-9ed6dcaabc0c","name":"In Scope","targets":[{"id":"3ba64258-1b63-4f04-94eb-52afb55999e9","uri":"https://manage.statuspage.io","name":"manage.statuspage.io","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d9898c86-0aae-4f57-b708-3799a3fd4573","sortOrder":0},"sortOrder":0,"tags":[{"id":"2737f40b-dd43-41a3-bc20-94069ed37230","name":"Fastly","targetId":"3ba64258-1b63-4f04-94eb-52afb55999e9"},{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"3ba64258-1b63-4f04-94eb-52afb55999e9"},{"id":"3585ef4a-cd09-429b-ad25-5777064e59c5","name":"Moment.js","targetId":"3ba64258-1b63-4f04-94eb-52afb55999e9"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"3ba64258-1b63-4f04-94eb-52afb55999e9"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"3ba64258-1b63-4f04-94eb-52afb55999e9"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"3ba64258-1b63-4f04-94eb-52afb55999e9"},{"id":"c3412833-26e7-4bbd-907f-760d9da61232","name":"Newrelic","targetId":"3ba64258-1b63-4f04-94eb-52afb55999e9"}],"recentChangeFlags":null},{"id":"80b08196-886f-407a-aa5e-42b8b9db4165","uri":null,"name":"*.statuspage.io","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f7f4e06a-2494-4c97-9e39-abdc447caf43","sortOrder":0},"sortOrder":0,"tags":[{"id":"6f2f82a5-9ef3-4bc5-9d86-6634e03133e1","name":"Recon","targetId":"80b08196-886f-407a-aa5e-42b8b9db4165"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"80b08196-886f-407a-aa5e-42b8b9db4165"},{"id":"e591e8bc-d7f4-49ad-952f-98dee6c92653","name":"DNS","targetId":"80b08196-886f-407a-aa5e-42b8b9db4165"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"25b12c97-a7cb-46b1-833c-687d865f7798","p1MaxCents":400000,"p1MinCents":400000,"p2MaxCents":150000,"p2MinCents":150000,"p3MaxCents":17500,"p3MinCents":17500,"p4MaxCents":10000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":4000,"max":4000},"2":{"min":1500,"max":1500},"3":{"min":175,"max":175},"4":{"min":100,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"b95fbd1c-4733-449d-add6-436f1a8db845","code":"statuspage","state":"in_progress","endsAt":null,"bountyId":"bdc77ad4-eb1d-4ec7-bf28-ee28a9cb04c4","startsAt":"2014-03-05T09:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/28c0/23ec/6022bc42/ddca52b471e3ce27a2d600c0b9285b1b_bounty-logo-atlassian.png","logoBackgroundColor":"#0052CC","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2014-03-05T09:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/statuspage","changelogs":"/engagements/statuspage/changelog","submissions":null,"announcements":"/engagements/statuspage/announcements","hallOfFame":"/engagements/statuspage/hall_of_fames","crowdstream":"/engagements/statuspage/crowdstream"},"announcementsCount":2,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/statuspage/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=statuspage\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/statuspage/engagement_subscribers","engagementChangelogsUrl":"/engagements/statuspage/changelog","publishedAt":"2026-04-07T21:21:10.467Z","engagementChangelogUrl":"/engagements/statuspage/changelog/67774d34-82ea-4d04-bfdf-89141a724bbb","createUserFeedbacksUrl":"/engagements/statuspage/feedbacks","engagementCrowdstreamUrl":"/engagements/statuspage/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}