52235 policies in database
Link to program      
2013-12-03
2019-08-02
OpenSSL (IBB) logo
Thank
Gift
HOF
Reward

Reward

500 $ 

OpenSSL (IBB)

OpenSSL has become the de facto standard for enabling cryptographically secure communication, and its integrity is of critical importance to preserving the privacy of all Internet users. The project's exceptional security track record has made the discovery of potential security vulnerabilities an increasingly difficult task. The security researchers who succeed in this challenge deserve our gratitude.

Bounty Qualification

The project maintainers have final decision on which issues constitute security vulnerabilities. The Panel will respect their decision, and we ask that you do as well. Our rewards are tied to the security severity level as determined by the project.

The project maintainers have final decision on which issues constitute security vulnerabilities. The Panel will respect their decision, and we ask that you do as well.

Only versions currently supported by the upstream project are eligible. Please verify your issue is present in a current release before submission.

It's important to keep in mind that not all submissions will qualify for a bounty, and that the decision to award a bounty is entirely at the discretion of the Panel.

Submission Process

  • Disclose a previously unknown security vulnerability directly to the project maintainers.
  • Follow the disclosure process established by the project maintainers.
  • Clearly demonstrate the security vulnerability. Respect the time of the project volunteers as they cannot invest significant effort into incomplete reports. Low-quality reports may be disqualified.
  • Once a public security advisory has been issued, please submit a report here. You must not send us the details of the vulnerability until it has been validated, accepted, and publicly disclosed by the project maintainers.

In Scope

Scope Type Scope Name
web_application

https://github.com/openssl/openssl


The progam has been crawled by Firebounty on 2013-12-03 and updated on 2019-08-02, 36 reports have been received so far.

FireBounty © 2015-2024

Legal notices | Privacy policy