Bug Bounties

Evernote

Powered by: 

Allows bounty splitting: 

Average time to first program response: 8

Average time to bounty awarded null: 250

Average time to report resolved: 

Handle evernote

Managed program: true

Name: Evernote

Offers bounties: true

Offers swag: false

Response efficiency percentage: 98

Submission state: open

Url: https://hackerone.com/evernote

Website: http://evernote.com

In scope:

  • Asset identifier: 281796108
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: 406056744
  • Asset type: DOWNLOADABLE_EXECUTABLES
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: MacOS
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: 9wzdncrfj3mb
  • Asset type: WINDOWS_APP_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: accounts.evernote.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: accounts.stage.evernote.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: This is the staging environment for accounts.evernote.com; vulnerabilities found here will not be eligible for bounty unless the vulnerability is also present in production.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: api.evernote.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: api.evernote.com is the API gateway into Evernote's microservice infrastructure. The microservice infrastructure is managed by Istio and is provisioned by Google Kubernetes Engine (GKE). Traffic is HTTP or gRPC, depending on the service being interacted with.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: api.stage.evernote.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: This is the staging environment for api.evernote.com; vulnerabilities found in this staging environment are not eligible for bounty *unless the vulnerability is verified in the corresponding production environments*.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.evernote.android
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: https://www.evernote.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: www.evernote.com serves the main Evernote web app. It also exposes several HTTP and Thrift endpoints that the Evernote mobile/desktop apps use to communicate with the service. Almost all endpoints on the www. domain are routed by HAProxy to an array of Java based Tomcat/Struts shards.
  • Integrity requirements: 
  • Max severity: critical