Powered by: Allows bounty splitting:
Average time to first program response: 11
Average time to bounty awarded null: 1462
Average time to report resolved: 1501
Handle gsa_bbp
Managed program: true
Name: GSA Bounty
Offers bounties: true
Offers swag: false
Response efficiency percentage: 94
Submission state: open
Url: https://hackerone.com/gsa_bbp
Website: http://gsa.gov
In scope: Asset identifier: *.code.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Bounty level: InitialIntegrity requirements: Max severity: criticalAsset identifier: *.login.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: *.search.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: account.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: admin-catalog-bsp.data.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: admin.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: alertmanager.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: api.data.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: api.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: catalog.data.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: From the data.gov Catalog, you will find many external references. These external sites and the data hosted there is **not in scope** for this program.Integrity requirements: Max severity: criticalAsset identifier: ci.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: dashboard-beta.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: dashboard.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: diagrams.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: federalist-docs.18f.govAsset type: URLAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: lowMax severity: mediumAsset identifier: federalist-proxy.app.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: federalist.18f.govAsset type: URLAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: mediumMax severity: highAsset identifier: federation.data.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: grafana.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: https://github.com/18f/docker-ruby-ubuntuAsset type: SOURCE_CODEAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: https://github.com/18f/federalistAsset type: SOURCE_CODEAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: https://github.com/18f/federalist-builderAsset type: SOURCE_CODEAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: https://github.com/18f/federalist-docker-buildAsset type: SOURCE_CODEAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: https://github.com/18f/federalist-proxyAsset type: SOURCE_CODEAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: https://github.com/18f/identity-idpAsset type: SOURCE_CODEAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: https://github.com/18f/identity-saml-railsAsset type: SOURCE_CODEAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: https://github.com/18f/identity-saml-sinatraAsset type: SOURCE_CODEAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: https://github.com/gsa/data.govAsset type: SOURCE_CODEAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: https://github.com/gsa/datagov-deployAsset type: SOURCE_CODEAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: idp.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: inventory.data.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: labs.data.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: login.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: logs-platform.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: logs.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: marketplace.fedramp.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Bounty level: InitialIntegrity requirements: Max severity: criticalAsset identifier: nessus.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: opslogin.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: prometheus.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: sdg.data.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: ssh.fr.cloud.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: tock.18f.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Bounty level: InitialIntegrity requirements: Max severity: criticalAsset identifier: www.data.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Integrity requirements: Max severity: criticalAsset identifier: www.fedramp.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Bounty level: InitialIntegrity requirements: Max severity: criticalAsset identifier: www.usa.govAsset type: URLAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: Bounty Level: Initial ($150 - $2,000)
The following subdomains are also in scope:
- analytics.usa.gov
- search.usa.gov
Chatbot, chat, and webform functionality on www.usa.gov is provided by SaaS providers, therefore we cannot guarantee being able to make mitigations in these areas. Integrity requirements: Max severity: critical