{"id":"8b9f0f91-371b-4297-931e-47ca45c06879","engagementId":"e28b3501-3542-40d0-88a6-7c308fa786c7","data":{"brief":{"id":"850204e0-da27-473b-83ab-632d2f9a38a3","name":"Cisco ThousandEyes Vulnerability Hunting aka Bug Bounty ","tagline":"ThousandEyes enables organizations to see and take action to maintain and optimize every digital journey that matters. ","description":"\u003cp\u003eCisco ThousandEyes enables organizations to see and take action to maintain and optimize every digital journey that matters. From application experience to hop-by-hop network path and performance, Cisco ThousandEyes provides end-to-end visibility from every user to any application over any network. Now, you can maximize the value of your digital investments and leverage them to drive differentiation in the market.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eNo technology is perfect, and ThousandEyes believes that working with skilled security researchers worldwide is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher and help us identify vulnerabilities in our targets. Good luck, and happy hunting!\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eImportant Guidelines: (Must Read)\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003ePlease ensure that the string \"\u003cstrong\u003eBugcrowd-\u0026lt;BugcrowdUsername\u0026gt;\u003c/strong\u003e\" is appended to your user agent for all HTTP/HTTPS traffic before performing any testing. Example instructions on how to modify the user agent string for Chrome can be found \u003ca href=\"https://developer.chrome.com/docs/devtools/device-mode/override-user-agent/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e, and for Burp Suite can be found \u003ca href=\"https://github.com/codewatchorg/Burp-UserAgent\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAutomated vulnerability scans are \u003cstrong\u003estrictly prohibited\u003c/strong\u003e (this includes any brute-force enumeration).\u003c/li\u003e\n\u003cli\u003eMaintaining \u003cstrong\u003econfidentiality\u003c/strong\u003e regarding any vulnerabilities you discover between ThousandEyes and yourself is crucial.  – \u003cstrong\u003eSee the Legal Information below\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eAt any point as a researcher, you are \u003cstrong\u003enot\u003c/strong\u003e allowed to modify/test any existing customer data or download any information other than from the Trial account or ThousandEyes grant to which you have been given access.  – \u003cstrong\u003eSee the Legal Information below\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eIt's strictly forbidden to conduct any form of \u003cstrong\u003eDenial of Service\u003c/strong\u003e testing. If you identify a vector by which DoS can be performed, please get in touch with USSR@thousandeyes.com or submit a submission write-up.\u003c/li\u003e\n\u003cli\u003ePlease note that as a bug bounty program participant, you play a crucial role in maintaining the security and availability of this live production environment.\u003c/li\u003e\n\u003cli\u003eThis is a Private Program, so you must refrain from discussing program details, including Program name, scope, Vulnerability details, bounty structure, account information, or any other detail to anyone who is not a Bugcrowd employee or member of this Program. When collaborating with other Finders on the Program, do so securely, per the disclosure requirements listed in Bugcrowd's \u003ca href=\"https://www.bugcrowd.com/resource/code-of-conduct/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCode of Conduct\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003ePlease clearly follow account creation guidelines for testing, including account naming and email conventions. Your submission may only be accepted if you adhere to those guidelines.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases, a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher, and the opportunity to appeal and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eAny domain/property of ThousandEyes not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTarget Information (In-Scope for Reward):\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://app.thousandeyes.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eapp.thousandeyes.com\u003c/a\u003e\u003c/strong\u003e—This is our web application platform, a core component of ThousandEyes SaaS that Customers use to create network performance monitoring tests, alerts, and reports.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://www.thousandeyes.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ewww.thousandeyes.com\u003c/a\u003e\u003c/strong\u003e—This is our company website. It provides information about our services, allows new users to create accounts, and directs existing users to the web application platform.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eapi.thousandeyes.com\u003c/strong\u003e—This is our customer-accessible API. It allows programmatic interaction with the web application platform.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eThousandEyes Enterprise Agent (Linux)\u003c/strong\u003e - The ThousandEyes platform uses agents to run tests against targets configured for measurement. An agent is a Linux server running custom ThousandEyes software, which checks in with an agent collector to obtain instructions from the ThousandEyes platform. \u003ca href=\"https://docs.thousandeyes.com/product-documentation/global-vantage-points/enterprise-agents\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eMore information\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eThousandEyes Endpoint Agent (Windows)\u003c/strong\u003e - The ThousandEyes Endpoint Agent is an application installed on user endpoint machines to collect network- and application-layer performance data when users access specific websites from monitored networks. \u003ca href=\"https://docs.thousandeyes.com/product-documentation/global-vantage-points/endpoint-agents\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eMore information\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eOther than the above, everything else is considered out of scope. Additional details on what is out of scope are below on this page.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003eAccessing the offerings:\u003c/h2\u003e\n\n\u003cp\u003eTo register for an account, please go \u003ca href=\"https://www.thousandeyes.com/signup\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePlease sign up for an account using your @bugcrowdninja.com email address (see here for more info regarding @bugcrowdninja.com emails \u003ca href=\"https://researcherdocs.bugcrowd.com/docs/your-bugcrowdninja-email-address\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://researcherdocs.bugcrowd.com/docs/your-bugcrowdninja-email-address\u003c/a\u003e). \u003cstrong\u003eIf you don't use your @bugcrowdninja address, your account will not be accepted, and you may be IP banned if you proceed to test\u003c/strong\u003e\n\u003c/li\u003e\n\u003cli\u003eUse Bugcrowd for the First, Last, and Company name fields.\u003c/li\u003e\n\u003cli\u003eThis will forward a request to our team, and your account will be activated within one business day.\u003c/li\u003e\n\u003cli\u003eA new organization will be created for you, and the account used to sign up will permit you to be an Organization Admin. You can also make other users with lower-level privileges - researchers are encouraged to create other users to test vertical privilege escalation issues, etc.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eUseful links(Documentation):\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAPI Documentation*: \u003ca href=\"https://developer.thousandeyes.com/v6/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eDeveloper Documentation*: \u003ca href=\"http://developer.thousandeyes.com/v6/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eGetting Started with ThousandEyes*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000CmnbKAC\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eRole-Based Access Control*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000CmnLKAS\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eAgent Types*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA044000000CnvICAS\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eWhat is an Enterprise Agent? Working with Agent settings*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000CmnbKAC\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eFirewall configuration for Enterprise agents*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA044000000CnBtCAK\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eGetting started with Endpoint Agent*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000CmpZKAS\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eHow to set up the Virtual appliance*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000CmnwKAC\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eWorking with the dashboard*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000CmmdKAC\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eWorking with Test settings*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000Cmn7KAC\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eWorking with Alerts*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA044000000CnBqCAK_How-Alerts-work\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eWorking with Reports*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage?articleIdParam=kA0E0000000CmnTKAS\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eAny other useful links can be accessed by searching on this page*: \u003ca href=\"https://success.thousandeyes.com/PublicArticlePage\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eFocus Areas:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eIDOR (Insecure Direct Object Reference)\u003c/li\u003e\n\u003cli\u003eAuthentication Bypass\u003c/li\u003e\n\u003cli\u003eAuthentication Related Issues\u003c/li\u003e\n\u003cli\u003eLocal Privilege Escalation\u003c/li\u003e\n\u003cli\u003eCross-Account Access\u003c/li\u003e\n\u003cli\u003eIncorrect Permissions\u003c/li\u003e\n\u003cli\u003eData Exposure\u003c/li\u003e\n\u003cli\u003eRemote Code Execution\u003c/li\u003e\n\u003cli\u003eSQL Injection (SQLi)\u003c/li\u003e\n\u003cli\u003eCommand Injection\u003c/li\u003e\n\u003cli\u003eLocal File Inclusion\u003c/li\u003e\n\u003cli\u003eRemote File Inclusion\u003c/li\u003e\n\u003cli\u003eDirectory Traversal\u003c/li\u003e\n\u003cli\u003eCross-Site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eOWASP Top 10\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope/Prohibited Activities and Vulnerabilities:\u003c/h2\u003e\n\n\u003cp\u003eThis program is designed to review and address security issues related to Cisco ThousandEyes. Please note that anything not explicitly listed as in-scope is considered out-of-scope.  \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eYou must not exploit, investigate, or target vulnerabilities against vendors used by ThousandEyes to provide the ThousandEyes offering, for example, you must not exploit, investigate, or target vulnerabilities against Amazon Web Services’ infrastructure.  \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you believe you have found a vulnerability that is outside of this program's scope but related to Cisco, please refer to the resources below: \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you need to report a vulnerability in a Cisco product, please contact psirt@cisco.com. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you need to contact Cisco regarding a security incident, please contact incidentresponse@cisco.com. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eCisco Systems Operational Infrastructure findings can be reported here: https://bugcrowd.com/ciscosecurity\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eFurther information can be found here: https://www.cisco.com/security \u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eThe support subdomain at ThousandEyes should not be tested in any shape or form\u003c/strong\u003e. This includes but is not limited to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eStarting a chat within the application, including sharelinks\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eInteracting with the ThousandEyes community via https://app.thousandeyes.com/sfdc/community\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eOpening support tickets via email\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eLeaked credentials from 3rd parties\u003c/strong\u003e This includes credential dumps found on websites, leaked credentials from indirect sources other than ThousandEyes, etc.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eManual crafting/ manual generation of malicious Agent traffic\u003c/strong\u003e    Do NOT attempt to send manually crafted or altered Agent traffic to the ThousandEyes application. Vulnerabilities that occur through test settings configured in the ThousandEyes web application \u003cem\u003eare valid vectors for attack\u003c/em\u003e. Vulnerabilities that involve manually (‘manual’ includes tools like Burp Intruder, ZAP, python scripts, etc.) sending traffic to the Agent data ingress points or controllers (c1.thousandeyes.com, eb.thousandeyes.com, etc.) \u003cem\u003eare not valid vectors for attack\u003c/em\u003e.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eEdited binaries do not qualify as valid findings\u003c/strong\u003e    If a vulnerability relies on the generation or use of a binary created by someone other than ThousandEyes, it will not be considered for this campaign.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eRegistration of Agents into Other Accounts\u003c/strong\u003e    Do not register Enterprise or Endpoint Agents into other ThousandEyes user accounts. Do not report the registration of an Agent into another account as a vulnerability.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eProhibited Tools and Methods.\u003c/strong\u003e  Do not use any tools or methods that have the potential to automatically generate volumes of traffic that may be considered a Denial of Service (DoS) event or in any way may impact our delivery of products and services.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eNo Social Engineering.\u003c/strong\u003e  Do not use any social engineering (e.g., phishing, vishing, smishing) methods concerning this Program. Findings that rely on social engineering to exploit (such as XSS links accessed from outside the application) will not be considered valid findings. In short, if your vulnerability requires an attacker to engage in Social Engineering, it will not be considered valid UNLESS the link is sent from the ThousandEyes application.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eDestroying Data and Interference with Services and Systems.\u003c/strong\u003e  Do not destroy data or interruption or degradation related, either directly or indirectly, to our services and systems.  Your research must be performed to view, capture, change, divert, or otherwise compromise any data that is not yours.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eNo Data Access Permitted.\u003c/strong\u003e  \u003cstrong\u003eYou are not permitted to intentionally view, capture, change, disclose, retain, or otherwise interact with any data, including ThousandEyes data or ThousandEyes’s customer data, that is not directly related to a Vulnerability subject to this Program. If you discover a Vulnerability that allows you to access the data of anyone else, including any ThousandEyes data or ThousandEyes’s customer data, immediately cease accessing such data upon detection of such Vulnerability and promptly notify ThousandEyes so we can promptly secure that data. See the Legal Information below.\u003c/strong\u003e   \u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003ePersonal Data Access Prohibited.\u003c/strong\u003e  You are not permitted to intentionally view, capture, change, disclose, control, process, or otherwise interact with any Personal Data concerning this Program. “Personal Data” means any information relating to an identifiable individual (also called Personally Identifiable Data). If you gain access to Personal Data, please immediately cease the activities giving rise to that access and promptly notify ThousandEyes so we can promptly secure that data. Do not identify names of individuals or ThousandEyes customers in your Reports. Do not include unnecessary information in your submission to investigate your Reports.  \u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAccessing other Accounts Prohibited.\u003c/strong\u003e\u003cbr\u003e\u003cbr\u003e\n\u003cstrong\u003eWhen investigating a Vulnerability, please only target your account. Never intentionally attempt to access anyone else's data, and do not engage in any activity that would damage ThousandEyes, its customers, partner community, employees, or others.\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAutomated Vulnerability Scanning.\u003c/strong\u003e\u003cbr\u003e\n\u003cstrong\u003ePlease note that using automated vulnerability scanning tools like Nuclei or Nessus is strictly prohibited in our program.  Additionally, Turbo Intruder is permitted ONLY to test unique functionality that only Turbo Intruder can find. Ensure you are only limiting this to 15 requests. If there's abuse, you will be removed from the program.\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eProhibited Activities\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eAll of the following activities are prohibited: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities resulting from violations of Program Policy and terms.\u003c/li\u003e\n\u003cli\u003eVulnerabilities not directly impacting ThousandEyes.\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eClickjacking on pages with no sensitive actions.\u003c/li\u003e\n\u003cli\u003eCross-site request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions.\u003c/li\u003e\n\u003cli\u003eAttacks requiring MITM or physical access to a user's device.\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without a working Proof of Concept.\u003c/li\u003e\n\u003cli\u003eComma Separated Values (CSV) injection without demonstrating a Vulnerability.\u003c/li\u003e\n\u003cli\u003eMissing best practices in SSL/TLS configuration.\u003c/li\u003e\n\u003cli\u003eAny activity that could lead to the disruption or denial of our service (DoS).  If you are unsure about such a possible disruption, please get in touch with ussr@thousandeyes.com before proceeding.\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eContent spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS.\u003c/li\u003e\n\u003cli\u003eRate limiting or brute force issues on non-authentication endpoints.\u003c/li\u003e\n\u003cli\u003eMissing best practices in Content Security Policy.\u003c/li\u003e\n\u003cli\u003eMissing HttpOnly or Secure flags on cookies.\u003c/li\u003e\n\u003cli\u003eMissing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.).\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users of outdated or unpatched browsers [Less than two stable versions behind the latest released stable version].\u003c/li\u003e\n\u003cli\u003eSoftware version disclosure / Banner identification issues / Descriptive error messages or headers (e.g., stack traces, application or server errors).\u003c/li\u003e\n\u003cli\u003ePublic Zero-day vulnerabilities that have had an official patch for less than one month will be awarded on a case-by-case basis.\u003c/li\u003e\n\u003cli\u003eTabnabbing.\u003c/li\u003e\n\u003cli\u003eOpen redirect - unless an additional security impact can be demonstrated.\u003c/li\u003e\n\u003cli\u003eIssues that require unlikely user interaction.\u003c/li\u003e\n\u003cli\u003eMissing CSP (Content Security Policy) Configuration\u003c/li\u003e\n\u003cli\u003eVulnerabilities reported by automated tools (e.g., Burp Suite)\u003c/li\u003e\n\u003cli\u003eCORS Issue without a working POC\u003c/li\u003e\n\u003cli\u003ePresence of Auto-complete attribute on Web forms\u003c/li\u003e\n\u003cli\u003eReports about weak password policy\u003c/li\u003e\n\u003cli\u003eUsername E-mail enumeration via forgot password\u003c/li\u003e\n\u003cli\u003eServer version disclosure\u003c/li\u003e\n\u003cli\u003eFindings from applications or systems not listed in the Targets section\u003c/li\u003e\n\u003cli\u003eFunctional UI/UX bugs and spelling mistakes\u003c/li\u003e\n\u003cli\u003eDefacing any site or resource. Report if you think you can do it and how, but don’t do it\u003c/li\u003e\n\u003cli\u003eUnder the Thousand Eyes' Customer Success Community (https://success.thousandeyes.com/PublicFeedItemContent), any actions that are initiated from the \"Ideas\" tab, including:\n\n\u003cul\u003e\n\u003cli\u003eCreating a new idea\u003c/li\u003e\n\u003cli\u003eCommenting on an existing idea\u003c/li\u003e\n\u003cli\u003eUpvoting an existing idea\u003c/li\u003e\n\u003cli\u003eDownvoting an existing idea\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eKnown Issues, ThousandEyes Web Application:\u003c/h3\u003e\n\n\u003cp\u003e30 May 2024 \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eUser-defined hyperlinks can be inserted into signup welcome emails. This has been assessed as a Low-Risk issue.\u003c/li\u003e\n\u003cli\u003eAPI Access for documentation account (e.g., one can use the credentials provided in the official documentation to perform authenticated API requests)\u003c/li\u003e\n\u003cli\u003eLack of ‘adequate’ Content Security Policy on all domains\u003c/li\u003e\n\u003cli\u003eThere is a lack of sufficient Automation Protection on the Forgot Password form (e.g., the form can be used to send spam).\u003c/li\u003e\n\u003cli\u003eOverly permissive CORS Policy (on all domains)\u003c/li\u003e\n\u003cli\u003eAccount lockout logic - e.g., one can successfully enumerate valid account IDs via the lockout feature.\u003c/li\u003e\n\u003cli\u003eThe user ID is displayed in cookies Cookies and Request Headers\u003c/li\u003e\n\u003cli\u003eMultiple concurrent sessions allowed\u003c/li\u003e\n\u003cli\u003eLack of maximum session length for any application interface (or ‘Agent’ interface)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eKnown Issues, ThousandEyes Enterprise Agent:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny package-based vulnerabilities in the downloadable ‘Enterprise Agent’ images that are not sourced from or directly imposed by the ThousandEyes ‘Agent’ software (this includes all operating system patches and CIS hardening controls)\u003c/li\u003e\n\u003cli\u003eCertain ‘Agent’ interfaces may report a lack of clickjacking defense\u003c/li\u003e\n\u003cli\u003eHTTPS is not strictly enforced on Enterprise Agents\u003c/li\u003e\n\u003cli\u003eThe HTTPS web app on the appliance site lacks Strict Transport Security\u003c/li\u003e\n\u003cli\u003eSession Cookie not set with ‘Secure’ flag in the ‘Admin’ interface of the Virtual Appliance\u003c/li\u003e\n\u003cli\u003eAgents do not require approval to register to the ThousandEyes platform\u003c/li\u003e\n\u003cli\u003eAppliance-based ‘Agents’ contain known SSH CVEs labeled as ‘no-patch,’ i.e., “Will Not Fix” by Canonical\u003c/li\u003e\n\u003cli\u003eSelf-signed HTTPS hosts are by design. Customers can upgrade certs as required\u003c/li\u003e\n\u003cli\u003eA lack of ‘SECCOMP’ or similar controls for hardening container-based agent activities\u003c/li\u003e\n\u003cli\u003eCIS compliance violations of any ‘Agent’ type are treated as ‘known’ (not in scope)\u003c/li\u003e\n\u003cli\u003eAny ‘binary analysis’ (e.g., detection of allegedly vulnerable versions in raw strings) based findings on any downloadable ‘Agent’ artifact are not in scope\u003c/li\u003e\n\u003cli\u003eA lack of ‘required password complexity’ for the administrative HTTPS user\u003c/li\u003e\n\u003cli\u003eThe default user/pass combination for the ‘Agent’ HTTPS interface is not strong enough\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eKnown Issues, ThousandEyes Endpoint Agents:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny ‘CVE’ based detections that appear to be disclosed by ‘binary analysis,’ or related processes (not in scope)\u003c/li\u003e\n\u003cli\u003eAny ‘compile-time’ detections, including ‘security build-time options’ for any ThousandEyes installer or executable, are not in scope\u003c/li\u003e\n\u003cli\u003eThe ‘Endpoint Agent’ runs as SYSTEM on Windows operating systems\u003c/li\u003e\n\u003cli\u003eThe ‘Endpoint Agent’ is built uniquely per customer endpoint by the ThousandEyes application; as such, any identifying characteristics based on hashing or similar measures are not in scope\u003c/li\u003e\n\u003cli\u003eAny findings that are related to associated libraries being executed ‘only in secured environments’ are not considered to be in scope\u003c/li\u003e\n\u003cli\u003eDetections based on ‘certificates’ or ‘signatures’ regardless of the certificate authority or operating system provider, are not considered to be in scope\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eLegal Information\u003c/h2\u003e\n\n\u003cp\u003eIn addition to these Terms and Conditions regarding the Cisco ThousandEyes Program, there may be additional restrictions depending upon applicable local laws. \u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003e\u003cp\u003eThe parties to this Agreement are you and ThousandEyes. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\"ThousandEyes\" refers to ThousandEyes LLC. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eBy participating in the Program, investigating a potential vulnerability, or submitting a vulnerability, you affirm that you have not disclosed and agree that you will not disclose the vulnerability to anyone other than ThousandEyes. Absent ThousandEyes 's prior written consent, any disclosure outside of this process would violate this Agreement. You agree that money damages may not be a sufficient remedy for a breach of this paragraph by you and that ThousandEyes will be entitled to specific performance as a remedy for any such breach. Such remedy will not be deemed to be the exclusive remedy for any such breach but will be in addition to all other remedies available at law or equity to ThousandEyes. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eBy submitting information about a potential vulnerability, you are granting ThousandEyes a worldwide, royalty-free, non-exclusive license to use your submission for the purpose of addressing vulnerabilities in ThousandEyes’ products and services. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIn the event of substantially duplicate submissions, ThousandEyes may at its discretion provide a reward only for the earliest received submission. Eligibility for rewards, determination of the recipients, and amount of reward is at the discretion of ThousandEyes. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf issues reported to our bug bounty program affect a third party or another vendor, ThousandEyes reserves the right to forward details of the issue along to the party without further discussion with the researcher. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou are responsible for all taxes associated with and imposed on any reward you may receive from ThousandEyes. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou may only exploit, investigate, or target vulnerabilities against your own accounts and/or your own devices. Testing must not violate any law, or disrupt or compromise any data or access data that is not yours; intentional access of customer data other than your own is prohibited. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you inadvertently access proprietary customer, employee, or business related information during your testing, the information must not be used, disclosed, stored, or recorded in any way. In the event of inadvertent access to such data, you must delete such data immediately and notify ThousandEyes of such inadvertent access within your submission. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYour testing activities must not negatively impact ThousandEyes, ThousandEyes’ products or services generally, or ThousandEyes’ online environment availability or performance. ThousandEyes may choose not to remediate at its sole discretion. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eThis Agreement constitutes the entire agreement of the parties with respect to the items listed above. This Agreement is covered by California law. This Agreement may be amended or modified only by a subsequent agreement in writing. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf any portion of this Agreement is found to be illegal or unenforceable, then the parties will be relieved of their responsibilities arising under such portion, but only to the extent that such portion is illegal or unenforceable. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou must not be the author of the code with the vulnerability. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eYou must not be an employee or contractor of ThousandEyes or its affiliates, or a family member of an employee or contractor. \u003c/p\u003e\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003eTHOUSANDEYES RESERVES THE RIGHT TO MODIFY OR CANCEL THIS PROGRAM AT ANY TIME WITHOUT NOTICE. ALL PARTICIPANTS AND SUBMISSIONS ARE STRICTLY VOLUNTARY. THIS OFFER IS VOID WHERE PROHIBITED BY LAW AND IN PARTICIPATING, YOU MUST NOT VIOLATE ANY LAW. YOU ALSO MUST NOT DISRUPT ANY SERVICE OR COMPROMISE ANYONE’S DATA. \u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"ea28cb62-b833-4088-8e89-fe1942b77a70","name":"ThousandEyes Enterprise Agent","targets":[{"id":"bd30b806-0545-4a3a-ba3f-433a3f4e2624","uri":null,"name":"https://api.thousandeyes.com/","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c892844e-ead3-4f45-9c8a-e7a73a3628d0","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"bd30b806-0545-4a3a-ba3f-433a3f4e2624"},{"id":"cbf0ee58-c41b-4dee-9d08-cefd01f5d7d6","name":"HTTP","targetId":"bd30b806-0545-4a3a-ba3f-433a3f4e2624"}],"recentChangeFlags":null},{"id":"62368b50-888e-4201-816f-b4350b0d3c8c","uri":"https://app.thousandeyes.com/","name":"https://app.thousandeyes.com/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"9113f302-4c78-467a-b126-fed5a23ad55a","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"62368b50-888e-4201-816f-b4350b0d3c8c"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"62368b50-888e-4201-816f-b4350b0d3c8c"},{"id":"ce8ff3cd-4d54-4404-8321-6351781551a3","name":"Vue.js","targetId":"62368b50-888e-4201-816f-b4350b0d3c8c"},{"id":"eaa69542-87cd-413a-9b74-3e75f9fb01e4","name":"Angular","targetId":"62368b50-888e-4201-816f-b4350b0d3c8c"}],"recentChangeFlags":null},{"id":"8065c56f-448f-4488-885e-55d94bb8d6d1","uri":"https://www.thousandeyes.com/","name":"https://www.thousandeyes.com/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"2b430950-db51-455a-bcef-911d5eefa86c","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"8065c56f-448f-4488-885e-55d94bb8d6d1"},{"id":"3585ef4a-cd09-429b-ad25-5777064e59c5","name":"Moment.js","targetId":"8065c56f-448f-4488-885e-55d94bb8d6d1"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"8065c56f-448f-4488-885e-55d94bb8d6d1"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"8065c56f-448f-4488-885e-55d94bb8d6d1"}],"recentChangeFlags":null},{"id":"e521609e-49de-4b3b-8df7-ffaa5d833105","uri":"","name":"ThousandEyes Enterprise Agent","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a9ad39b1-7fbe-4712-a5b6-a195b8376cd6","sortOrder":0},"sortOrder":0,"tags":[{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"e521609e-49de-4b3b-8df7-ffaa5d833105"}],"recentChangeFlags":null},{"id":"def7e308-5007-4f72-aff8-d65983a903b6","uri":"","name":"ThousandEyes Endpoint Agent ","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4a81c574-9c6d-4059-ab07-c841b9d6e5c2","sortOrder":0},"sortOrder":0,"tags":[{"id":"9c63a0f4-0db6-40da-85f0-65d0aa72bfbe","name":"Windows","targetId":"def7e308-5007-4f72-aff8-d65983a903b6"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"86b07e5e-68fa-42c5-bf2f-aa329d138999","p1MaxCents":450000,"p1MinCents":410000,"p2MaxCents":175000,"p2MinCents":150000,"p3MaxCents":85000,"p3MinCents":60000,"p4MaxCents":25000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":4100,"max":4500},"2":{"min":1500,"max":1750},"3":{"min":600,"max":850},"4":{"min":200,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"44ba7768-840a-49a5-9a43-5fb8e6947535","name":"Out of scope","targets":[{"id":"d4532904-8122-4e3f-abe9-d3f634d40640","uri":null,"name":"https://blog.thousandeyes.com/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"25336091-ee84-4c3e-8fbd-6352117d7bec","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d4532904-8122-4e3f-abe9-d3f634d40640"}],"recentChangeFlags":null},{"id":"d62e9e5c-4a8e-44e2-92b8-0557641b992a","uri":"","name":"https://app.thousandeyes.com/sfdc/community","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"63e29e36-727e-4858-8eb5-ec5663dd8fc5","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"e28b3501-3542-40d0-88a6-7c308fa786c7","code":"thousandeyes-og","state":"in_progress","endsAt":null,"bountyId":"6644c264-2f5b-45b4-8ade-fdfdda135bbd","startsAt":"2021-11-09T19:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/eb4d/6d03/45c7aaeb/daa295c2a67a9bbd46ed2b47f351f8e0_Cisco_ThousandEyes_Logo_Stacked_Orange_Blue.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-01-16T19:17:29.141Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/thousandeyes-og","changelogs":"/engagements/thousandeyes-og/changelog","submissions":null,"announcements":"/engagements/thousandeyes-og/announcements","hallOfFame":"/engagements/thousandeyes-og/hall_of_fames","crowdstream":"/engagements/thousandeyes-og/crowdstream"},"announcementsCount":9,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/thousandeyes-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=thousandeyes-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/thousandeyes-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/thousandeyes-og/changelog","publishedAt":"2026-01-16T19:17:29.168Z","engagementChangelogUrl":"/engagements/thousandeyes-og/changelog/8b9f0f91-371b-4297-931e-47ca45c06879","createUserFeedbacksUrl":"/engagements/thousandeyes-og/feedbacks","engagementCrowdstreamUrl":"/engagements/thousandeyes-og/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}