Powered by:
Allows bounty splitting:
Average time to first program response: 9
Average time to bounty awarded null: 45
Average time to report resolved: 1159
Handle kiwicom
Managed program: true
Name: Kiwi.com
Offers bounties: true
Offers swag: true
Response efficiency percentage: 99
Submission state: open
Url: https://hackerone.com/kiwicom
Website: https://www.kiwi.com
In scope:
Asset identifier: *.kiwi.comAsset type: URLAvailability requirement: lowConfidentiality requirement: mediumEligible for bounty: trueEligible for submissions: trueInstruction: Mostly branded versions of our main www.kiwi.com site, please report vulnerabilities only for www.kiwi.com and don't duplicate it here.Integrity requirements: mediumMax severity: critical
Asset identifier: *.skypicker.comAsset type: URLAvailability requirement: lowConfidentiality requirement: mediumEligible for bounty: trueEligible for submissions: trueInstruction: APIs & internal tools.Integrity requirements: mediumMax severity: critical
Asset identifier: auth.skypicker.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: Authentication API used on www.kiwi.com.Integrity requirements: mediumMax severity: critical
Asset identifier: com.skypicker.SkypickerAsset type: APPLE_STORE_APP_IDAvailability requirement: lowConfidentiality requirement: mediumEligible for bounty: trueEligible for submissions: trueInstruction: **Primary target** - Available in [App Store](https://itunes.apple.com/bs/app/kiwi-com-cheap-flight-tickets/id657843853)Integrity requirements: mediumMax severity: critical
Asset identifier: com.skypicker.mainAsset type: GOOGLE_PLAY_APP_IDAvailability requirement: lowConfidentiality requirement: mediumEligible for bounty: trueEligible for submissions: trueInstruction: **Primary target** - Available in the [Play Store](https://play.google.com/store/apps/details?id=com.skypicker.main)Integrity requirements: mediumMax severity: critical
Asset identifier: https://github.com/kiwicom/*Asset type: SOURCE_CODEAvailability requirement: mediumConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Note that archived projects are out of scope.Integrity requirements: lowMax severity: high
Asset identifier: jobs.kiwi.comAsset type: URLAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Hiring page, no sensitive information, likely no impact on our company.Integrity requirements: lowMax severity: medium
Asset identifier: tequila.kiwi.comAsset type: URLAvailability requirement: mediumConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: B2B platform. Backend API requests are proxied via **tequila-api.kiwi.com** & **api.tequila.kiwi.com**Integrity requirements: mediumMax severity: critical
Asset identifier: www.kiwi.comAsset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: Our main websiteIntegrity requirements: highMax severity: critical
Asset identifier: www.kiwi.com/storiesAsset type: URLAvailability requirement: mediumConfidentiality requirement: lowEligible for bounty: trueEligible for submissions: trueInstruction: Online travel magazine Kiwi.com Stories, with very limited impact on our sites & infrastructure.Integrity requirements: lowMax severity: high