Bug Bounties

Mattermost

Powered by: 

Allows bounty splitting: 

Average time to first program response: 58

Average time to bounty awarded null: 150

Average time to report resolved: 1239

Handle mattermost

Managed program: false

Name: Mattermost

Offers bounties: true

Offers swag: true

Response efficiency percentage: 91

Submission state: open

Url: https://hackerone.com/mattermost

Website: https://mattermost.com

In scope:

  • Asset identifier: *.mattermost.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium



  • Asset identifier: 978516833
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Latest IPA can be downloaded from here: https://github.com/mattermost/mattermost-mobile/releases
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: Mattermost Desktop
  • Asset type: DOWNLOADABLE_EXECUTABLES
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: The [Mattermost Desktop App](https://developers.mattermost.com/contribute/desktop/) is an Electron wrapper around the web app project. The source code is available in [GitHub](https://github.com/mattermost/desktop). The desktop app runs on Windows, Linux, and macOS. [Installation instructions available here](https://docs.mattermost.com/install/desktop-app-install.html)
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: Mattermost Plugins
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: - [Jira Plugin](https://github.com/mattermost/mattermost-plugin-jira) - [Zoom Plugin](https://github.com/mattermost/mattermost-plugin-zoom) - [GitHub Plugin](https://github.com/mattermost/mattermost-plugin-github) - [Autolink Plugin](https://github.com/mattermost/mattermost-plugin-autolink) - [WelcomeBot Plugin](https://github.com/mattermost/mattermost-plugin-welcomebot) - [Custom Attributes Plugin](https://github.com/mattermost/mattermost-plugin-custom-attributes) - [AWS SNS Plugin](https://github.com/mattermost/mattermost-plugin-aws-SNS) - [Playbooks Plugin](https://github.com/mattermost/mattermost-plugin-playbooks) Documentation and setup instructions are available in the README of the repository. General documentation: https://docs.mattermost.com
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: Mattermost Source Code
  • Asset type: SOURCE_CODE
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: [Server](https://github.com/mattermost/mattermost-server) | [Webapp](https://github.com/mattermost/mattermost-webapp) | [Mobile](https://github.com/mattermost/mattermost-mobile) ### Deploy your self-hosted Mattermost instance [via Docker](https://mattermost.com/deploy/) | [via Tar](https://docs.mattermost.com/install/install-tar.html) Detailed setup instructions for individual components are available here: [Server](https://developers.mattermost.com/contribute/server/developer-setup/) | [Webapp](https://developers.mattermost.com/contribute/webapp/developer-setup/) | [Mobile](https://developers.mattermost.com/contribute/mobile/developer-setup/)
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: Other publicly-released plugins
  • Asset type: SOURCE_CODE
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: This asset is for plugins that Mattermost doesn't officially support. As informational only, we accept reports about important security issues with community plugins. Mattermost will handle contacting the plugin author and will provide guidance for the community member to implement a fix.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.mattermost.rn
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: The latest APK can be downloaded from here: https://github.com/mattermost/mattermost-mobile/releases The public beta release containing the latest features is also in scope and can be accessed on the Play Store under the identifier [com.mattermost.rnbeta](https://play.google.com/store/apps/details?id=com.mattermost.rnbeta)
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: h1-*your-own-instance*.cloud.mattermost.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Create your own free instance by signing up at https://customers.mattermost.com/cloud/signup ## Important Notes - Remember to prefix your instance name with `h1-` so that it’s easily identifiable. - Please use your own cloud instance for testing. - Never use any other cloud instances. - Please adhere to the Program Rules as mentioned in our Program Policy.
  • Integrity requirements: 
  • Max severity: critical