ntpd-rs is an open-source implementation of the Network Time Protocol written in Rust, with support for the Network Time Security protocol and a focus on exposing a minimal attack surface.
This bug bounty program is paid for by the Sovereign Tech Resilience program.
You can find our repository on Github
Every valid report that helps us improve the security of the project is welcome, however, in order to qualify for monetary rewards the following eligibility requirements must be met at a minimum:
CVSS is used to rate and categorize vulnerabilities. Vulnerabilities will be publicly disclosed after sufficient time has passed and fixes have been backported where needed, if deemed necessary in coordination with mainstream Linux distributions.
Advisories will be published on the advisory page of our GitHub repository, and where deemed necessary as CVEs and on external mailing-lists like oss-security.
We handle the full disclosure process and expect submitters not to disclose any findings themselves. If requested, we will fully credit the reporters in the advisories.
The process for external reporting is described on GitHub
Scope Type | Scope Name |
---|---|
web_application | https://github.com/pendulum-project/ntpd-rs |
web_application | https://github.com/pendulum-project/timestamped-socket |
web_application | https://github.com/pendulum-project/clock-steering |
Scope Type | Scope Name |
---|---|
undefined | Known protocol limitations related to the NTP protocol |
undefined | Anything related to the NTPv5 and/or NTS Pool KE features (both disabled by default), unless it impacts other parts of the software |
undefined | Anything related to the CI pipeline or GitHub related hosting |
web_application | Anything related to *.ntpd-rs.pendulum-project.org |
This program have been found on Yeswehack on 2024-07-08.
FireBounty © 2015-2025