Bug Bounties

Hy-Vee

Powered by: 

Allows bounty splitting: 

Average time to first program response: 5

Average time to bounty awarded null: 

Average time to report resolved: 6785

Handle hy-vee

Managed program: true

Name: Hy-Vee

Offers bounties: false

Offers swag: false

Response efficiency percentage: 94

Submission state: open

Url: https://hackerone.com/hy-vee

Website: http://hy-vee.com

In scope:

  • Asset identifier: *.hy-vee.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: ##Please create a test account using your @ wearehackerone.com email [Register test account here](https://accounts.hy-vee.com/auth/realms/customer/login-actions/registration?client_id=hy-vee-dot-com&tab_id=tRYt_C3mtmc&contentOnly=undefined)
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: Other Hy-Vee owned asset
  • Asset type: OTHER
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: If you believe you have found a vulnerability on an application owned by Hy-Vee other than *.hy-vee.com, you may safely report it to us here on our Vulnerability Disclosure Program. Thank you!
  • Integrity requirements: 
  • Max severity: critical