Powered by: Allows bounty splitting:
Average time to first program response: 20
Average time to bounty awarded null: 180
Average time to report resolved: 2200
Handle figma
Managed program: true
Name: Figma
Offers bounties: true
Offers swag: false
Response efficiency percentage: 94
Submission state: open
Url: https://hackerone.com/figma
Website: https://figma.com
In scope: Asset identifier: Figma Atlassian AppAsset type: OTHERAvailability requirement: highConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: https://marketplace.atlassian.com/apps/1217865/figma-for-jira
Unauthorized access via this app or the APIs that this app uses is also in scope. Integrity requirements: highMax severity: criticalAsset identifier: Figma Desktop AppAsset type: OTHERAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: Figma Slack AppAsset type: OTHERAvailability requirement: highConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: https://figma.slack.com/apps/A01N2QYSA81-figma-and-figjam?tab=more_infoIntegrity requirements: highMax severity: criticalAsset identifier: Figma for Microsoft TeamsAsset type: OTHERAvailability requirement: highConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: https://appsource.microsoft.com/en-us/product/office/wa200004521?tab=overviewIntegrity requirements: highMax severity: criticalAsset identifier: Figma iOS and Android appsAsset type: OTHERAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: api.figma.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: highMax severity: criticalAsset identifier: www.figma.comAsset type: URLAvailability requirement: lowConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: We are primarily looking for high/critical vulnerabilities in the system.Integrity requirements: highMax severity: critical