Bug Bounties

Starbucks

Powered by: 

Allows bounty splitting: 

Average time to first program response: 7

Average time to bounty awarded null: 299

Average time to report resolved: 793

Handle starbucks

Managed program: true

Name: Starbucks

Offers bounties: true

Offers swag: false

Response efficiency percentage: 95

Submission state: open

Url: https://hackerone.com/starbucks

Website: http://www.starbucks.com

In scope:

  • Asset identifier: Other assets
  • Asset type: OTHER
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: If you have found a vulnerability in a Starbucks site or app not contained within this list, you can still submit, and Starbucks will triage the report. These types of reports will not result in a monetary reward but valid reports that are resolved can improve your reputation score on the HackerOne platform.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: Subdomain Takeover (SDTO)
  • Asset type: OTHER
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Subdomain Takeovers will be evaluated on their severity considering cookie scoping, historical significance and potential traffic volume. They maybe bounty eligible or alternately informative as determined by their security impact to Starbucks. Refer to the Appropriate Proof of Concepts section of this policy for information on how to construct a valid proof of concept for these reports.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: app.starbucks.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks US https://app.starbucks.com
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: card.starbucks.com.sg
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Rewards Singapore https://card.starbucks.com.sg
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: cart.starbucks.co.jp
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Japan Store Cart/Checkout https://cart.starbucks.co.jp/
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.starbucks.br
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Brazil ios app https://itunes.apple.com/br/app/starbucks-brasil/id1041179480
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.starbucks.br
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Brazil Android App. https://play.google.com/store/apps/details?id=com.starbucks.br
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.starbucks.cn
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks China Android App. https://play.google.com/store/apps/details?id=com.starbucks.cn
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.starbucks.de
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Germany ios app. https://itunes.apple.com/de/app/starbucks-deutschland/id948562829
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.starbucks.de
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Germany Android App https://play.google.com/store/apps/details?id=com.starbucks.de
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.starbucks.fr
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks France ios app. https://itunes.apple.com/fr/app/starbucks-france/id943993603
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.starbucks.fr
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks France Android App https://play.google.com/store/apps/details?id=com.starbucks.fr
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.starbucks.jp
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Japan ios app https://itunes.apple.com/jp/app/id1113037275
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.starbucks.jp
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Japan Android App. https://play.google.com/store/apps/details?id=com.starbucks.jp
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.starbucks.mobilecard
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks USA Android app. https://play.google.com/store/apps/details?id=com.starbucks.mobilecard
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.starbucks.mystarbucks
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks US ios app. https://itunes.apple.com/us/app/starbucks/id331177714
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.starbucks.mystarbucks.kr
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Korea iOS App https://itunes.apple.com/us/app/%EC%8A%A4%ED%83%80%EB%B2%85%EC%8A%A4/id466682252
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.starbucks.sbuxsingapore
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Singapore iOS App https://itunes.apple.com/sg/app/starbucks-singapore/id574621564
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.starbucks.singapore
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Singapore Android App https://play.google.com/store/apps/details?id=com.starbucks.singapore Assets eligible for bounty referenced directly by this app: https://mobile.starbucks.com.sg
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: com.starbuckschina.mystarbucksmoments
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks China ios app https://itunes.apple.com/us/app/starbucks-china/id499819758
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: gift.starbucks.co.jp
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks e-gift Japan https://gift.starbucks.co.jp/
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: login.starbucks.co.jp
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Japan Login page https://login.starbucks.co.jp/
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: openapi.starbucks.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks digital service capabilities to 3rd party business partner(s)/cooperators via standard Open API.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: secureui.starbucks.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Payment Processing https://secureui.starbucks.com/
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: www.starbucks.ca
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Canada https://www.starbucks.ca/
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: www.starbucks.co.jp
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Japan https://www.starbucks.co.jp
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: www.starbucks.co.kr
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Korea https://www.istarbucks.co.kr https://www.starbucks.co.kr istarbucks.co.kr used to be the main Starbucks site in the region, but is now a redirector to starbucks.co.kr. Bugs in the redirector or in the www.starbucks.co.kr site are accepted under this scope.
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: www.starbucks.co.uk
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks UK www.starbucks.co.uk
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: www.starbucks.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks US https://www.starbucks.com/
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: www.starbucks.com.br
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Brazil https://www.starbucks.com.br/
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: www.starbucks.com.cn
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks China https://www.starbucks.com.cn/
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: www.starbucks.com.sg
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Singapore https://www.starbucks.com.sg/
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: www.starbucks.de
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Germany https://www.starbucks.de/
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: www.starbucks.fr
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks France https://www.starbucks.fr/
  • Integrity requirements: 
  • Max severity: critical



  • Asset identifier: www.starbucksreserve.com
  • Asset type: URL
  • Availability requirement: 
  • Confidentiality requirement: 
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Starbucks Reserve https://www.starbucksreserve.com/
  • Integrity requirements: 
  • Max severity: critical