Bug Bounties

StrongDM

Powered by: 

Allows bounty splitting: 

Average time to first program response: 38

Average time to bounty awarded null: 

Average time to report resolved: 268

Handle strongdm

Managed program: true

Name: StrongDM

Offers bounties: false

Offers swag: true

Response efficiency percentage: 100

Submission state: open

Url: https://hackerone.com/strongdm

Website: https://www.strongdm.com

In scope:

  • Asset identifier: *.sdm.network
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: SDM Client - Windows (sdm.exe)
  • Asset type: DOWNLOADABLE_EXECUTABLES
  • Availability requirement: medium
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: strongDM Client application for installation on Windows platforms
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: SDM Client - macOS (sdm.app)
  • Asset type: DOWNLOADABLE_EXECUTABLES
  • Availability requirement: medium
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: strongDM client application for installation on macOS (Darwin) systems
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: SDM Gateway - *nix
  • Asset type: DOWNLOADABLE_EXECUTABLES
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: strongDM Gateway application for installation on *nix-based servers
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: StrongDM Go SDK
  • Asset type: SOURCE_CODE
  • Availability requirement: low
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: https://github.com/strongdm/strongdm-sdk-go
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: StrongDM Java SDK
  • Asset type: SOURCE_CODE
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: https://github.com/strongdm/strongdm-sdk-java
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: StrongDM Python SDK
  • Asset type: SOURCE_CODE
  • Availability requirement: low
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: https://github.com/strongdm/strongdm-sdk-python
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: StrongDM Ruby SDK
  • Asset type: SOURCE_CODE
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: https://github.com/strongdm/strongdm-sdk-ruby
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: api.strongdm.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: app.strongdm.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: strongDM Gateway Docker/Kuberneters/Fargate Relay Container Image
  • Asset type: OTHER
  • Availability requirement: medium
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: https://quay.io/repository/sdmrepo/relay?tab=info
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: www.strongdm.com
  • Asset type: URL
  • Availability requirement: low
  • Confidentiality requirement: low
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: low
  • Max severity: medium