Instruction: *.lab.epam.com is a development staging environment, and please consider that fake PII data can be used there.
We will accept the following vulnerabilities as valid submissions for *.lab.epam.com:
* SQL/NoSQL injection
* RCE
* SSRF
* XXE Injections
* Path traversal
* Stored-cross site scripting
* PII leakage issues
* Security misconfigurations with demonstrated security impact
* Any other vulnerabilities that will give the possibility threat actor to read files from the server/execute commands/retrieve sensitive information
Integrity requirements:
Max severity: critical
Asset identifier: *.opensource.epam.com
Asset type: OTHER
Availability requirement:
Confidentiality requirement:
Eligible for bounty: true
Eligible for submissions: true
Instruction:
Integrity requirements:
Max severity: critical
Asset identifier: *.projects.epam.com
Asset type: URL
Availability requirement:
Confidentiality requirement:
Eligible for bounty: true
Eligible for submissions: true
Instruction:
Integrity requirements:
Max severity: critical
Asset identifier: 1135407607
Asset type: APPLE_STORE_APP_ID
Availability requirement:
Confidentiality requirement:
Eligible for bounty: true
Eligible for submissions: true
Instruction:
Integrity requirements:
Max severity: critical
Asset identifier: Disclosure of the credentials or confidential information
Asset type: OTHER
Availability requirement:
Confidentiality requirement:
Eligible for bounty:
Eligible for submissions: true
Instruction: Leaks of credentials and confidential information from malware logs/dumps/intelligence services/public sources would be accepted as valid issues but won't be rewarded with a bounty.
Integrity requirements:
Max severity: critical
Asset identifier: Subdomain takeover
Asset type: OTHER
Availability requirement:
Confidentiality requirement:
Eligible for bounty: true
Eligible for submissions: true
Instruction: Subdomain takeover will be awarded a 150$ bounty. Subdomain takeover will be rewarded for ONLY "In scope" targets. All others will be accepted as valid findings but won't be rewarded.