The Deezer platform provides an innovative music streaming service that has attracted millions of users worldwide. Deezer lets them instantly play the music they want to hear and guarantees high-quality sound, diversification and personalized music curation.
Deezer is committed to working with security experts across the world to stay up to date with the latest security techniques. If you have discovered a security issue that you believe we should know about, please let us know about it and we'll do our best to quickly correct the issue.
We take security issues seriously and we're big believers in protecting privacy and security. Our bug bounty programs has been put in place to give a tip of the hat to software security researchers.
Please adhere to the following rules while performing research on this program:
We are happy to thank everyone who submits valid reports which help us improve the security of Deezer, however only those that meet the following eligibility requirements may receive a monetary reward:
Reward amounts are based on:
In the context of this program, we do not intend to encourage, accept or reward reports of leaks that are not applicable to our program’s scope and identified outside of our program’s scope, such as:
Also, in order not to encourage dark and grey economies, in particular the purchase, resale and trade of identifiers or stolen information, as well as all types of dangerous behavior (e.g. social engineering, ...), we will not accept or reward any report based on information whose source is not the result of failure on the part of our organization or one of our employees/service providers.
This excludes, but is not limited to:
Source of leak is in-scope | Source of leak belongs to Niantic, Inc but is out-of-scope | Source of leak does not belong to Niantic, Inc and is out-of-scope | |
---|---|---|---|
Impact is in-scope (e.g. valid credentials on an in-scope asset) | Eligible | Eligible | Not Eligible |
Impact is out-of-scope (e.g. valid credentials for an out-of-scope asset) | Eligible | Not Eligible | Not Eligible |
As a complement to the Program’s rules and testing policy :
If your Deezer account is deactivated by our system because it detected a malicious attempt, please contact the Bounty Program manager to ask for its re-activation.
The user agent bug-bounty-hunterName (replace hunterName by your nickname) is mandatory during your tests. If you don’t use it, we may ban you from the program for security reasons.
Note that it can happen sometimes that our teams are already aware and working on a vulnerability before your reported it, we'll thank you for having reported it nevertheless in that case the report won't be eligible for a reward.
Any non-security related issue will not be eligible for a money reward. Bugs, wrong interface or API behavior, etc. should be sent to http://support.deezer.com/requests/new
Scope Type | Scope Name |
---|---|
android_application | https://play.google.com/store/apps/details?id=deezer.android.app |
android_application | https://play.google.com/store/apps/details?id=com.deezer.zen |
api | wellbeing.deezer.com |
api | pipe.deezer.com |
ios_application | https://apps.apple.com/fr/app/deezer-musique-podcast/id292738169 |
ios_application | https://apps.apple.com/be/app/zen-by-deezer-m%C3%A9ditation/id1597326355 |
web_application | www.deezer.com |
web_application | connect.deezer.com |
web_application | api.deezer.com |
web_application | payment.deezer.com |
web_application | zen.deezer.com |
web_application | wellbeing.dzcdn.net |
web_application | account.deezer.com |
Scope Type | Scope Name |
---|---|
undefined | desktop apps (electron) |
undefined | All domains or subdomains not listed in the above list of 'Scopes' |
web_application | developers.deezer.com |
web_application | partners.deezer.com |
web_application | cdn-files.deezer.com |
web_application | cdn-content.deezer.com |
web_application | support.deezer.com |
web_application | deezercommunity.com |
web_application | deezer-blog.com |
web_application | deezer-brandsolutions.com |
web_application | deezerjobs.com |
Firebounty have crawled on 2019-01-29 the program Deezer Bug Bounty Program on the platform Yeswehack.
FireBounty © 2015-2024