{"id":"799c3f25-0d05-4448-bef5-3585bd979103","engagementId":"cd479b05-3664-47d1-9809-e9f874c8d3c3","data":{"brief":{"id":"e301ba9a-737a-445d-b1f7-1eaa5acbea15","name":"Trello","tagline":"Trello keeps track of everything, from the big picture to the minute details.","description":"\u003cp\u003eTrusted by millions, Trello is a visual collaboration tool that creates a shared perspective on any project. Trello’s boards, lists, and cards enable you to organize and prioritize your personal and work life in a fun, flexible, and rewarding way.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards and Bounty Rules:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eNote: Atlassian uses CVSS to consistently score security vulnerabilities. Where discrepancies between the VRT and CVSS score exist, Atlassian will defer to the CVSS score to determine the priority.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eTo qualify for a bounty you must:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eReport a qualifying vulnerability that is in the scope of our program (also below)\u003c/li\u003e\n\u003cli\u003eBe the first person to report the vulnerability\u003c/li\u003e\n\u003cli\u003eAdhere to our disclosure guidelines (see below)\u003c/li\u003e\n\u003cli\u003eOnly test against your own accounts and data\u003c/li\u003e\n\u003cli\u003eBe reasonable with automated scanning methods so as to not degrade services\u003c/li\u003e\n\u003cli\u003eRefrain from disclosing the vulnerability until we've addressed it\u003c/li\u003e\n\u003cli\u003eCommunicate with our security team exclusively via Bugcrowd (the security team will be way more impressed by your exploits than our support or social media teams)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eAccess/Credentials\u003c/h3\u003e\n\n\u003cp\u003eYou are free to make as many accounts as needed to test on Trello - please ensure that you use your \u003cem\u003e@bugcrowdninja.com\u003c/em\u003e email address.\u003c/p\u003e\n\n\u003ch2\u003eDisclosure Request Guidance\u003c/h2\u003e\n\n\u003cp\u003eSubmissions that meet the following requirements will be considered for disclosure upon request:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe submission has been accepted\u003c/li\u003e\n\u003cli\u003eThe reported vulnerability has been fixed and released in production\u003c/li\u003e\n\u003cli\u003eThe submission does not regard a customer instance or a customer’s account \u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003ch3\u003eReports must include the following:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eA Proof of Concept\u003c/li\u003e\n\u003cli\u003eDetailed steps on how to reproduce the vulnerability\u003c/li\u003e\n\u003cli\u003eExplanation of how the attack could be executed in a real world scenario to compromise user accounts or data\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eVulnerabilities affecting blog.trello.com will only qualify for a bounty if they include a working proof of concept showing how the issue can compromise user data on trello.com.\u003cbr\u003e\n\u003cem\u003eOther domains (e.g. trello-attachments.s3.amazonaws.com) or subdomains not listed above (e.g. e.trello.com, help.trello.com) and 3rd party services, are not in scope and will not qualify for a bounty.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch3\u003eOut-of-Scope\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eCustomer instances and data are explicitly out of scope.\u003c/li\u003e\n\u003cli\u003eAny Board/Card/Data that you are not an owner of - do not impact Trello customers in any way.\u003c/li\u003e\n\u003cli\u003eAny Trello billing system. However, specific endpoints that are used inside of a target are in scope. For example, if a REST endpoint is proven to be called from one of the targets, then that endpoint is considered to be in scope. However, all other endpoints are not considered to be in scope, as they are not called from the instance at any stage.\u003c/li\u003e\n\u003cli\u003eAny internal or development services\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eThe following finding types are specifically excluded from the bounty\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe use of Automated scanners is strictly prohibited (we have these tools too - don't even think about using them)\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g. Stack Traces, application or server errors).\u003c/li\u003e\n\u003cli\u003eHTTP 404 codes/pages or other HTTP non-200 codes/pages.\u003c/li\u003e\n\u003cli\u003eFingerprinting / banner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eDisclosure of known public files or directories, (e.g. robots.txt).\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eCSRF on forms that are available to anonymous users (e.g. the contact form).\n\n\u003cul\u003e\n\u003cli\u003eCSRF attacks that require knowledge of the CSRF token (e.g. attacks involving a local machine).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eLogout Cross-Site Request Forgery (logout CSRF).\u003c/li\u003e\n\u003cli\u003eContent Spoofing.\u003c/li\u003e\n\u003cli\u003ePresence of application or web browser ‘autocomplete’ or ‘save password’ functionality.\u003c/li\u003e\n\u003cli\u003eCookies missing secure/HttpOnly.\u003c/li\u003e\n\u003cli\u003eLack of Security Speedbump when leaving the site.\u003c/li\u003e\n\u003cli\u003eWeak Captcha / Captcha Bypass.\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force and account lockout not enforced.\u003c/li\u003e\n\u003cli\u003eOPTIONS HTTP method enabled.\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration.\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers, specifically (https://www.owasp.org/index.php/List_of_useful_HTTP_headers), e.g.\n\n\u003cul\u003e\n\u003cli\u003eStrict-Transport-Security.\u003c/li\u003e\n\u003cli\u003eX-Frame-Options.\u003c/li\u003e\n\u003cli\u003eX-XSS-Protection.\u003c/li\u003e\n\u003cli\u003eX-Content-Type-Options.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy, X-Content-Security-Policy, X-WebKit-CSP.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy-Report-Only.\u003c/li\u003e\n\u003cli\u003eCache-Control and Pragma\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eHTTP/DNS cache poisoning.\u003c/li\u003e\n\u003cli\u003eSSL/TLS Issues, e.g.\n\n\u003cul\u003e\n\u003cli\u003eSSL Attacks such as BEAST, BREACH, Renegotiation attack.\u003c/li\u003e\n\u003cli\u003eSSL Forward secrecy not enabled.\u003c/li\u003e\n\u003cli\u003eSSL weak/insecure cipher suites.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eNo Load testing (DoS/DDoS etc) is allowed on the instance.\n\n\u003cul\u003e\n\u003cli\u003eThis includes application DoS as well as network DoS.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSelf-XSS reports will not be accepted.\n\n\u003cul\u003e\n\u003cli\u003eSimilarly, any XSS where local access is required (i.e. User-Agent Header injection) will not be accepted. The only exception will be if you can show a working off-path MiTM attack that will allow for the XSS to trigger.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerabilities that are limited to unsupported browsers will not be accepted (i.e. \"this exploit only works in IE6/IE7\"). A list of supported browsers can be found \u003ca href=\"https://confluence.atlassian.com/display/Cloud/Supported+browsers\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eKnown vulnerabilities in used libraries, or the reports that an Atlassian product uses an outdated third party library (e.g. jQuery, Apache HttpComponents etc) unless you can prove exploitability.\u003c/li\u003e\n\u003cli\u003eMissing or incorrect SPF records of any kind.\u003c/li\u003e\n\u003cli\u003eSource code disclosure vulnerabilities.\u003c/li\u003e\n\u003cli\u003eInformation disclosure of non-confidential information (e. g. issue id, project id, commit hashes).\u003c/li\u003e\n\u003cli\u003eThe ability to upload/download viruses or malicious files to the platform.\u003c/li\u003e\n\u003cli\u003eEmail bombing\u003c/li\u003e\n\u003cli\u003eFlooding\u003c/li\u003e\n\u003cli\u003eRate limiting\u003c/li\u003e\n\u003cli\u003eCSV Injection\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eRules\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou must ensure that customer data is not affected in any way as a result of your testing. Please ensure you're being non-destructive whilst testing and are only testing on instances that you own.\u003c/li\u003e\n\u003cli\u003eIn addition to above, customer instances are not to be accessed in any way (i.e. no customer data is accessed, customer credentials are not to be used or \"verified\")\n\n\u003cul\u003e\n\u003cli\u003eIf you believe you have found sensitive customer data (e.g., login credentials, API keys etc) or a way to access customer data (i.e. through a vulnerability) report it, but do not attempt to successfully validate if/that it works.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cem\u003eUse of any automated tools/scanners is strictly prohibited\u003c/em\u003e and will lead to you being removed from the program (trust us, we have those tools too).\u003c/li\u003e\n\u003cli\u003eReports need to be submitted in plain text (associated pictures/videos are fine as long as they're in standard formats). Non-plain text reports (e.g. PDF, DOCX) will be asked to be resubmitted in plain text.\u003c/li\u003e\n\u003cli\u003eSufficiently similar access control issues should be grouped in one report. Atlassian defines “sufficiently similar” as issues that use the same configuration for bypassing a particular control, which may be used on multiple related vulnerable endpoints or actions (User X can Create/Delete/Edit Resource Y).\u003c/li\u003e\n\u003cli\u003eGrants/awards are at the discretion of Atlassian and we withhold the right to grant, modify or deny grants. But we'll be fair about it.\u003c/li\u003e\n\u003cli\u003eTax implications of any payouts are the sole responsibility of the reporter.\u003c/li\u003e\n\u003cli\u003eDo NOT conduct non-technical attacks such as social engineering, phishing or unauthorized access to infrastructure.\u003c/li\u003e\n\u003cli\u003eDo NOT test the physical security of Trello offices, employees, equipment, etc.\u003c/li\u003e\n\u003cli\u003eThis bounty follows Bugcrowd’s standard disclosure terms.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eScoring\u003c/h3\u003e\n\n\u003cp\u003eA few issue types are not scored by their CVSS scores \u003cbr\u003e\nThese are typically higher severity, but will be rewarded as P4 issues:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eXSS Vulnerabilities where the script is blocked by the product's Content Security Policy, unless a bypass is documented as part of the submission\u003c/li\u003e\n\u003cli\u003eOpen Redirect bugs, and\u003c/li\u003e\n\u003cli\u003eBroken Access Control or Privilege Escalation bugs, where an Administrator is able to perform System Administrator actions.\n### Public Disclosure\nAt Atlassian, one of our values is Open Company, No Bullshit, we believe that vulnerability disclosure is a part of that value. We hold ourselves to the security bug fix service level objectives, found \u003ca href=\"https://www.atlassian.com/trust/security/bug-fix-policy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e, and will accept disclosure requests in the bug bounty program after the issue has been fixed and released in production. However, if the report contains any information regarding a customer instance or data the request will be rejected. If you are planning to disclose outside of the bug bounty, we ask that you give us reasonable notice and wait until the \u003ca href=\"https://www.atlassian.com/trust/security/bug-fix-policy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eassociated SLO\u003c/a\u003e has passed.\u003cbr\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eReporting Guidelines\u003c/h3\u003e\n\n\u003cp\u003eWhere applicable, please include the following information. This will greatly assist in the triage, validation, and acceptance processes and will result in more clear security risk communication and timely report acceptances.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eBrief summary (please include product versions affected/tested)\u003c/li\u003e\n\u003cli\u003ePrerequisites (including any products, user privileges, tools required, files prepared, web server configurations, or any other initial conditions to prior to initiating the proof of concept)\u003c/li\u003e\n\u003cli\u003eReproduction steps including vulnerable endpoints, parameters, payloads used, source of any scripts used, or command line inputs (burp requests, screenshots and recordings are \u003cstrong\u003ehighly\u003c/strong\u003e encouraged)\u003c/li\u003e\n\u003cli\u003eExpected results/behavior vs actual results/behavior (include any formal documentation, resources, or links that state the expected behavior)\u003c/li\u003e\n\u003cli\u003eAssessed security impact (as it relates to the Confidentiality, Integrity, and/or Availability of the product)\u003c/li\u003e\n\u003cli\u003ePossible mitigations, fixes, or security controls\u003c/li\u003e\n\u003cli\u003eReferences\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eSafe Harbor\u003c/h3\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYou are expected, as always, to comply with all applicable laws.\u003cbr\u003e\nIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further.\u003c/p\u003e\n\n\u003ch3\u003eThanks\u003c/h3\u003e\n\n\u003cp\u003eWe're happy to acknowledge security researchers that have helped us keep our users' data secure on our Hall of Fame page. \u003ca href=\"https://bugcrowd.com/trello/hall-of-fame\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://bugcrowd.com/trello/hall-of-fame\u003c/a\u003e\u003c/p\u003e","safeHarborStatus":null,"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"a3bda598-0a4e-446d-ac25-d6bdeca0c252","name":"In Scope","targets":[{"id":"de95628d-35b0-46d5-ac49-a7cc075acf1e","uri":null,"name":"trello.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"1b56e2b2-866b-4d4c-bf4e-d0b2f59584a7","sortOrder":0},"sortOrder":0,"tags":[{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"de95628d-35b0-46d5-ac49-a7cc075acf1e"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"de95628d-35b0-46d5-ac49-a7cc075acf1e"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"de95628d-35b0-46d5-ac49-a7cc075acf1e"}],"recentChangeFlags":null},{"id":"29da4e73-35f7-49cc-9fbf-36ee824bdee2","uri":null,"name":"api.trello.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a512f4e7-2f3a-4340-a349-2c5947e155cd","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"29da4e73-35f7-49cc-9fbf-36ee824bdee2"}],"recentChangeFlags":null},{"id":"c2092529-6931-43d5-9179-411e87aed132","uri":null,"name":"*.trello.services","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"61dd2948-c39b-4249-9eff-d11b163a58e1","sortOrder":0},"sortOrder":0,"tags":[{"id":"6f2f82a5-9ef3-4bc5-9d86-6634e03133e1","name":"Recon","targetId":"c2092529-6931-43d5-9179-411e87aed132"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"c2092529-6931-43d5-9179-411e87aed132"},{"id":"e591e8bc-d7f4-49ad-952f-98dee6c92653","name":"DNS","targetId":"c2092529-6931-43d5-9179-411e87aed132"}],"recentChangeFlags":null},{"id":"87650f60-1496-438b-b6ca-3a813a649cb2","uri":null,"name":"Trello Desktop Client","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b4e25e59-558a-49e5-90a7-3a02b46ed534","sortOrder":0},"sortOrder":0,"tags":[{"id":"47f8649b-7612-4d6d-bb41-c0078e628292","name":"Electron","targetId":"87650f60-1496-438b-b6ca-3a813a649cb2"},{"id":"9c63a0f4-0db6-40da-85f0-65d0aa72bfbe","name":"Windows","targetId":"87650f60-1496-438b-b6ca-3a813a649cb2"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"87650f60-1496-438b-b6ca-3a813a649cb2"},{"id":"c5df6ad0-33b4-40ac-b6dd-8d4038997d40","name":"macOS","targetId":"87650f60-1496-438b-b6ca-3a813a649cb2"}],"recentChangeFlags":null},{"id":"23a69c85-bd14-4a13-9c8d-cddcd6eba19f","uri":null,"name":"Trello Mobile App for Android","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"931e663b-28aa-450a-940b-7bce7c8d9c72","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"23a69c85-bd14-4a13-9c8d-cddcd6eba19f"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"23a69c85-bd14-4a13-9c8d-cddcd6eba19f"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"23a69c85-bd14-4a13-9c8d-cddcd6eba19f"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"23a69c85-bd14-4a13-9c8d-cddcd6eba19f"}],"recentChangeFlags":null},{"id":"93799fad-07c6-4470-86f7-eb171867b23f","uri":null,"name":"Trello Mobile App for iOS","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"3501cdd8-98bb-4b6f-a24c-f9660ab63e61","sortOrder":0},"sortOrder":0,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"93799fad-07c6-4470-86f7-eb171867b23f"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"93799fad-07c6-4470-86f7-eb171867b23f"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"93799fad-07c6-4470-86f7-eb171867b23f"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"93799fad-07c6-4470-86f7-eb171867b23f"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"93799fad-07c6-4470-86f7-eb171867b23f"}],"recentChangeFlags":null},{"id":"d38a3bc9-8a81-49ab-a444-4d1359a4090d","uri":"https://butlerfortrello.com/","name":"Butler for Trello","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f80c2459-0942-43f1-8bdd-d2ffdd9dc4c8","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d38a3bc9-8a81-49ab-a444-4d1359a4090d"}],"recentChangeFlags":null},{"id":"0e4181d1-52d4-4974-b135-dfbaea0cd137","uri":"https://trello.com/power-ups/55a5d917446f517774210011/calendar-power-up","name":"Calendar Power-Up","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e33dc7d1-3bee-4fc4-9c2e-c063078a17e5","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"cedfb330-85e9-4355-9884-b95e701f8b0d","uri":"https://trello.com/power-ups/55a5d917446f517774210012/card-aging","name":"Card Aging Power-Up","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ef2e363a-54b2-4c82-995a-1787e45b1fb3","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"f28940a1-c5ac-4c2b-b2db-7c29cf697ca5","uri":"https://trello.com/power-ups/5c2462c384ab8949b1724a20/list-limits","name":"List Limits Power-Up","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c94bead8-0602-4bf3-aa58-9a7f8c6737e4","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"0f3d1e4e-87b4-4b1f-bc61-dab01e87b306","uri":"https://trello.com/power-ups/55a5d917446f517774210013/voting","name":"Voting Power-Up","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d3ba2586-f39e-4d72-87f6-4ca74586a1ad","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"ef512e3e-76a1-4e30-ad12-e98457f31c16","uri":"https://trello.com/power-ups/6052d130068a8c0de7b022b4","name":"Microsoft Teams Integration","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f7b190ff-b1f7-4523-8d38-06a4a4cd2be4","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"90b6e548-67cc-4d9f-8f7f-e5dea0dd14ca","p1MaxCents":1200000,"p1MinCents":1200000,"p2MaxCents":400000,"p2MinCents":400000,"p3MaxCents":32500,"p3MinCents":32500,"p4MaxCents":25000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":12000,"max":12000},"2":{"min":4000,"max":4000},"3":{"min":325,"max":325},"4":{"min":250,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"c6bc53f3-67d3-414c-872f-cc25d70c72d5","name":"Out of Scope","targets":[{"id":"18eb8d0f-50f7-42fe-bce5-65a36b49659e","uri":"http://bugcrowd.com/atlassianapps","name":"First party (made-by-trello) power-ups other than those inscope are excluded from this program but can be reported to http://bugcrowd.com/atlassianapps","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d5c0ecfd-2ba5-4680-a9af-700f165dc48d","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"18eb8d0f-50f7-42fe-bce5-65a36b49659e"}],"recentChangeFlags":null},{"id":"29264c84-3e24-4fa0-bafc-853e37793867","uri":null,"name":"e.trello.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4be76c6d-6ba9-42af-9135-ea2c31906748","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"29264c84-3e24-4fa0-bafc-853e37793867"}],"recentChangeFlags":null},{"id":"7589758d-23f6-474a-aac4-9db41c0d89ba","uri":null,"name":"help.trello.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ed2f32a6-4fbc-4486-9cf0-088a296aedcc","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7589758d-23f6-474a-aac4-9db41c0d89ba"}],"recentChangeFlags":null},{"id":"a168370c-f41a-45cb-9cab-68ca325733f3","uri":null,"name":"trello-attachments.s3.amazonaws.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5a6c271f-ea32-4862-b28f-8c8237fa6538","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a168370c-f41a-45cb-9cab-68ca325733f3"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null},{"id":"13c9836d-25b2-4f0d-8e4c-d42a09a779ef","name":"Trello Third Party Powerups","targets":[{"id":"6e046b66-2ec6-4808-b1ba-112f72826e1b","uri":"","name":"Trello Third Party Powerups","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"051f5771-129c-46ee-852c-78cf4b6f92a8","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch3\u003eNote on Trello Third Party Powerups\u003c/h3\u003e\n\n\u003cp\u003eTrello Third Party Powerups are not officially under Atlassian ownership and do not follow the normal bug bounty security assessments. However, vulnerabilities found in Trello Third Party Powerups can be reported and we will make attempts to forward such reports to the creators of the Powerups. We do not guarantee the eligibility for a reward. Rewards may be considered on a \u003cstrong\u003ecase-by-case\u003c/strong\u003e basis if the vulnerability can affect Trello customers outside of the third party powerup (e.g. a valid XSS attack that can steal the Trello token of victim users). \u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAtlassian holds the right to eliminate rewards for third party powerups at any given time.\u003c/strong\u003e\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"cd479b05-3664-47d1-9809-e9f874c8d3c3","code":"trello","state":"in_progress","endsAt":null,"bountyId":"bdc77ad4-eb1d-4ec7-bf28-ee28a9cb04c4","startsAt":"2018-08-16T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/28c0/23ec/6022bc42/ddca52b471e3ce27a2d600c0b9285b1b_bounty-logo-atlassian.png","logoBackgroundColor":"#0052CC","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2018-08-16T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/trello","changelogs":"/engagements/trello/changelog","submissions":null,"announcements":"/engagements/trello/announcements","hallOfFame":"/engagements/trello/hall_of_fames","crowdstream":"/engagements/trello/crowdstream"},"announcementsCount":3,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/trello/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=trello\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/trello/engagement_subscribers","engagementChangelogsUrl":"/engagements/trello/changelog","publishedAt":"2026-04-07T21:21:13.219Z","engagementChangelogUrl":"/engagements/trello/changelog/799c3f25-0d05-4448-bef5-3585bd979103","createUserFeedbacksUrl":"/engagements/trello/feedbacks","engagementCrowdstreamUrl":"/engagements/trello/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}