Powered by: Allows bounty splitting:
Average time to first program response: 20
Average time to bounty awarded null: 217
Average time to report resolved:
Handle coda_bbp
Managed program: true
Name: Coda
Offers bounties: true
Offers swag: false
Response efficiency percentage: 100
Submission state: open
Url: https://hackerone.com/coda_bbp
Website: https://coda.io/
In scope: Asset identifier: Coda Chrome ExtensionAsset type: OTHERAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Link: https://chrome.google.com/webstore/detail/coda-browser-extension/cdgkmagmdldlpiglliebaajdpdkigcbi?hl=enIntegrity requirements: mediumMax severity: highAsset identifier: codacontent.ioAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: codahosted.ioAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: https://*.coda.io/*Asset type: URLAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: lowMax severity: mediumAsset identifier: https://airflow-prod.coda.io/*Asset type: URLAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: lowMax severity: mediumAsset identifier: https://airflow-prod.ops.coda.io/*Asset type: URLAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: lowMax severity: mediumAsset identifier: https://coda.io/*Asset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: https://coda.io/signup/emailAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Please use your HackerOne designated email when signing up (**`@wearehackerone.com`**), and furthermore please avoid any automated testing or brute-forcing as that may lead to your accounts or IP getting locked out and also create issues on our end.
Integrity requirements: Max severity: criticalAsset identifier: https://data.coda.io/*Asset type: URLAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: lowMax severity: mediumAsset identifier: https://head.coda.io/*Asset type: URLAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: lowMax severity: mediumAsset identifier: https://infra.coda.io/*Asset type: URLAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: lowMax severity: mediumAsset identifier: https://shiny.ops.coda.io/*Asset type: URLAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: lowMax severity: mediumAsset identifier: https://staging.coda.io/*Asset type: URLAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: lowMax severity: mediumAsset identifier: https://user-profile-prod.coda.io/*Asset type: URLAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: lowMax severity: mediumAsset identifier: https://user-profile-test.coda.io/*Asset type: URLAvailability requirement: noneConfidentiality requirement: lowEligible for bounty: Eligible for submissions: trueInstruction: Integrity requirements: noneMax severity: lowAsset identifier: io.codaAsset type: APPLE_STORE_APP_IDAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Link: https://apps.apple.com/us/app/coda/id1397968110
Coda's native apps make heavy use of the same endpoints and UX that's used by the mobile website. That being said, there are some differences and we invite security reports pertaining to our iOS and Android apps. Please be sure to follow the same guidelines for setting up an account in our mobile apps as on https://coda.io.Integrity requirements: Max severity: criticalAsset identifier: io.coda.codaappAsset type: GOOGLE_PLAY_APP_IDAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Link: https://play.google.com/store/apps/details?id=io.coda.codaapp
Coda's native apps make heavy use of the same endpoints and UX that's used by the mobile website. That being said, there are some differences and we invite security reports pertaining to our iOS and Android apps. Please be sure to follow the same guidelines for setting up an account in our mobile apps as on https://coda.io.Integrity requirements: Max severity: critical