Under Armour AppSec

  • $125 – $2,500 per vulnerability
  • Partial safe harbor

Brute force logins are out of Scope testing

There have been updates to the out of scope testing as of July 14, 2022. This update brings about the following changes with links to relevant resources:

The findings that will be considered out of scope moving forward:
-Brute force on login or forgot password page and account lockout

As always, please be sure to review the program brief in detail, and if you have any questions, please reach out support@bugcrowd.com.

Happy Hunting!