Banner object (1)

Hack and Take the Cash !

836 bounties in database
  Back Link to program      
18/01/2019
Apache Kafka (European Commission - DIGIT) logo
Thanks
Gift
Hall of Fame
Reward

Reward

Apache Kafka (European Commission - DIGIT)

Introduction

This project has been sponsored by the European Commission as part of the EU- Free and Open Source Software Auditing (EU-FOSSA) project designed to improve the security of free software.

This program will be open for submissions for 8 weeks, though rewards may be processed beyond the 8 week period in order to allow for full evaluation of the impact of valid vulnerability reports.

Note: This program has now been extended for a further two months until the 14th of July

Disclosure Policy

  • Follow HackerOne's disclosure guidelines.
  • Let us know as soon as possible upon discovery of a potential security issue, and we'll make every effort to quickly resolve the issue.
  • Please provide detailed reports with reproducible steps demonstrating a plausible exploitation scenario.
  • If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.
  • Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.
  • The project maintainers have final decision on which issues constitute security vulnerabilities. We will respect their decision, and we ask that you do as well.

Exclusions

While researching, we'd like to ask you to refrain from:

  • Denial of service
  • Spamming
  • Social engineering (including phishing) of staff or contractors

Scope

The PoC must work on the master branch of https://github.com/apache/kafka __, or the latest build. Older builds are explicitly out of scope.

Out of Scope

Building Apache Kafka

Check https://github.com/apache/kafka/blob/trunk/README.md __to learn how to build the software.

Rewards

Our rewards are based on the severity of a vulnerability. HackerOne uses CVSS 3.0 (Common Vulnerability Scoring Standard) to calculate severity. We will update the program over time based on feedback, so please give us feedback on any part of the program you think we can improve on.

Our rewards are based on the severity of a vulnerability. HackerOne uses CVSS 3.0 (Common Vulnerability Scoring Standard) to calculate severity. We will update the program over time based on feedback, so please give us feedback on any part of the program you think we can improve on.

A bonus structure is in place from the 14th of June to 14th July 2019

SEVERITY | CVSS SCORE | REWARD | Temporary Bonus Structure
---|---|---|---
critical | 9.0 - 10.0 | ~~€5000~~ | €7500
High | 7.0 - 8.9 | ~~€2500~~ | €3250
Medium | 4.0 - 6.9 | ~~€1000~~ | €1300
Low | 0.1 - 3.9 | ~~€250~~ | €325

Critical severity bugs - €7500:

  • Remote Code Execution

High severity bugs - €3250:

  • Code Execution without user intervention

Medium severity bugs - €1300:

  • Code Execution with user intervention
  • High-impact Crashes
  • Infinite loops

Low severity bugs - €325:

  • Information leaks
  • Crashes
  • OOM

Bonus

There is a 20% bonus for including a fix in the report, when accepted by the maintainers. Please use the guidelines outlined here: https://kafka.apache.org/contributing __

Note : The 20% bonus is calculated off the new bonus structure.

Safe Harbor

Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.

Thank you for helping keep Apache Kafka and our users safe!

If you have any questions or concerns on this Challenge, please contact tpm- sl@hackerone.com.


FireBounty © 2015-2019

Legal notices