52235 policies in database
Link to program      
2016-06-17
2019-09-25
Nextcloud logo
Thank
Gift
HOF
Reward

Reward

50 $ 

Nextcloud

We're inviting researchers all over the globe to take a look at Nextcloud and bring it's security to the next level. If you're interested in learning how we handle security you can read more about it on our dedicated security page.

Program policy

We know how valuable your time is and employ a "No bullshit policy" that boils down to: Don't be a jerk. Instead of bothering you with a huge list of exclusions we're going to tell you what we're especially looking after:

  1. Bugs within Nextcloud server and apps supported by Nextcloud GmbH (Note: see scope below for all qualifying and packaged components. Third-party apps from the AppStore are not part of our bounty program.)

  2. Bugs within the mobile iOS and Android sync clients

  3. Bugs within the desktop sync clients for Mac, Windows, and Linux

A bug is for us something that actively allows an attacker to escalate their privileges. Something like "Attacker can delete arbitrary files of other users" is fine, "Missing X-Frame-Options on the download servers" not so much. At the moment we are also considering Denial of Service not a reward worthy vulnerability. (we will acknowledge you though!)

Found a security bug in one of the above-mentioned components? Awesome! Just report it here and we will get back to you. These components are also for what monetary rewards are awarded. Bonus points if you check back with our threat model before.

Found a bug in one of our websites or so? While we can't offer you any monetary reward we will acknowledge the issue and happily accept reports for it via this platform as well. But please do not run any Denial of Service attacks against our infrastructure or extract user data. Please do also refrain from using automated testing tools against our infrastructure or disclosing bugs to other parties before we have published a patch.

We believe in transparency about our security, so any valid vulnerabilities discovered are always publicly disclosed after a grace period.

Rewards

Our rewards are based on severity and range up to $10,000. To give you some guidance we have compiled below list:

| Impact | Definition | Highest possible reward |

|----------|--------------------------------------------------------------------------------------------------------------------------|-------------|

| Critical | Gaining remote code execution on the server as a non-admin user. (i.e. RCE) | $10,000 |

| High | Gaining access to complete user data of any other user. (i.e. Auth Bypass) | $4,000 |

| Medium | Limited disclosure of user data or attacks granting access to a single users' user session. (i.e. XSS with CSP bypass) | $1,500 |

| Low | Very limited disclosure of user data or attacks involving a very high unlikely amount of user interaction. | $500 |

In Scope

Scope Type Scope Name
android_application

com.nextcloud.client

android_application

com.nextcloud.talk2

application

Desktop Client

ios_application

it.twsweb.Nextcloud

ios_application

com.nextcloud.Talk

undefined

nextcloud/server

undefined

nextcloud/activity

undefined

nextcloud/files_accesscontrol

undefined

nextcloud/3rdparty

undefined

nextcloud/files_pdfviewer

undefined

nextcloud/files_texteditor

undefined

nextcloud/firstrunwizard

undefined

nextcloud/notifications

undefined

nextcloud/password_policy

undefined

nextcloud/user_saml

undefined

nextcloud/files_automatedtagging

undefined

nextcloud/files_retention

undefined

nextcloud/serverinfo

undefined

nextcloud/nextcloud_announcements

undefined

nextcloud/logreader

undefined

nextcloud/survey_client

undefined

nextcloud/updater

undefined

nextcloud/spreed

undefined

nextcloud/photos

undefined

nextcloud/mail

undefined

nextcloud/files_rightclick

undefined

nextcloud/privacy

undefined

nextcloud/recommendations

undefined

nextcloud/viewer

undefined

nextcloud/text

undefined

nextcloud/circles

undefined

nextcloud/data_request

undefined

nextcloud/files_antivirus

undefined

nextcloud/fulltextsearch

undefined

daita/files_fulltextsearch_tesseract

undefined

nextcloud/flow_notifications

undefined

nextcloud/files_fulltextsearch

undefined

nextcloud/groupfolders

undefined

nextcloud/guests

undefined

nextcloud/sharepoint

undefined

nextcloud/socialsharing

undefined

nextcloud/suspicious_login

undefined

nextcloud/terms_of_service

undefined

nextcloud/twofactor_totp

undefined

nextcloud/twofactor_u2f

undefined

nextcloud/user_oidc

undefined

nextcloud/workflow_script

undefined

nextcloud/calendar

undefined

nextcloud/contacts

undefined

nextcloud/richdocuments

undefined

nextcloud/onlyoffice

undefined

nextcloud/end_to_end_encryption

undefined

nextcloud/deck

undefined

nextcloud/fulltextsearch_elasticsearch

web_application

https://download.nextcloud.com

web_application

https://nextcloud.com

web_application

https://portal.nextcloud.com

web_application

https://support.nextcloud.com

web_application

https://stats.nextcloud.com

web_application

https://static.apps.nextcloud.com

web_application

https://crm.nextcloud.com

web_application

https://scan.nextcloud.com/

web_application

https://apps.nextcloud.com/

web_application

https://lookup.nextcloud.com

web_application

https://surveyserver.nextcloud.com

web_application

https://push-notifications.nextcloud.com

web_application

https://lists.nextcloud.com

web_application

https://docs.nextcloud.com

web_application

https://knowledge.nextcloud.com

web_application

https://projects.nextcloud.com

web_application

https://usercontent.apps.nextcloud.com

web_application

https://help.nextcloud.com

web_application

https://logs.nextcloud.com

web_application

https://auth.nextcloud.com

web_application

https://newsletter.nextcloud.com

web_application

https://pushfeed.nextcloud.com

web_application

https://customerupdates.nextcloud.com

web_application

https://updates.nextcloud.com

Out of Scope

Scope Type Scope Name
web_application

https://cloud.nextcloud.com

web_application

https://drone.nextcloud.com

web_application

https://demo.nextcloud.com

web_application

https://conf.nextcloud.com

web_application

https://sentry.nextcloud.com

web_application

try.nextcloud.com


The progam has been crawled by Firebounty on 2016-06-17 and updated on 2019-09-25, 152 reports have been received so far.

FireBounty © 2015-2024

Legal notices | Privacy policy