Description

## Vulnerability Disclosure Program We are committed to maintaining the security of our products, services, and customers. We recognize that independent security researchers play an important role in identifying vulnerabilities that may otherwise go undetected. This Vulnerability Disclosure Program (VDP) provides security researchers with a clear and responsible channel to report security vulnerabilities affecting our in-scope assets. We welcome reports that help us identify weaknesses in our applications, APIs, authentication mechanisms, authorization controls, and other security-relevant functionality. We will review and triage submitted reports and, where appropriate, work with the relevant teams to validate and remediate confirmed vulnerabilities. Please provide sufficient technical information, including a clear description and proof of concept, to allow us to reproduce and assess the reported issue. ### Responsible Testing Researchers participating in this program are expected to: * Act in good faith and conduct testing in a manner that does not unnecessarily affect the availability, confidentiality, or integrity of our systems or data. * Limit testing to the minimum activity required to demonstrate the vulnerability. * Avoid accessing, modifying, deleting, or extracting data belonging to other users or customers. * Avoid actions that could negatively affect our production systems or other users. * Not perform denial-of-service or distributed denial-of-service testing, brute-force attacks, spam, social engineering, physical attacks, or other disruptive activities. * Respect the privacy of our customers, users, and employees. * Keep vulnerability information confidential and not publicly disclose vulnerabilities until remediation or disclosure has been coordinated with us. For authentication bypasses and similar vulnerabilities, demonstrating the ability to circumvent the relevant security control is sufficient. Researchers should not continue exploitation to demonstrate additional impact where doing so could affect our systems or data. Researchers who wish to perform authenticated testing or more extensive exploitation are encouraged to request access to our separate private bug bounty program. ### Reporting Please submit vulnerabilities through this VDP with enough information for our security team to reproduce and validate the issue. Reports should clearly describe the affected asset, the steps required to reproduce the vulnerability, the expected and actual behavior, and the potential security impact. We appreciate responsible security research and the contribution of the security community to improving the security of our products and services.

Bounties

This is a responsible disclosure program without bounties.

This Vulnerability Disclosure Program does not guarantee or provide monetary rewards for vulnerability submissions. Researchers should not expect compensation for submitting a report through this program.

All submitted reports will be reviewed and handled according to our vulnerability disclosure and triage process. The absence of a reward does not affect our commitment to reviewing valid security reports and addressing confirmed vulnerabilities appropriately.

If a reported vulnerability also falls within the scope of one of our private bug bounty programs, we may, at our sole discretion, provide a reward equivalent to the applicable bounty amount. Any such reward is determined on a case-by-case basis and is not guaranteed.

Participation in this VDP does not create any entitlement, expectation, or contractual obligation to receive compensation. The decision to provide a reward, including the amount and eligibility, remains entirely at our discretion.

Rules of engagement
Not applicable
Intigriti - {Username}
Not allowed
Not applicable

By participating in this program, you agree to:

  • Respect the Community Code of Conduct
  • Respect the Intigriti Terms and Conditions
  • Respect the scope of the program
  • Not discuss or disclose vulnerability information without prior written consent (including PoC's on YouTube and Vimeo)

Validation times

Vulnerability Severity Time to validate
Exceptional 2 Working days
Critical 2 Working days
High 5 Working days
Medium 15 Working days
Low 15 Working days

This remains at the discretion of mateco to award.

Assets
2
Internal Services – Transitioning to VPN - Do not have Auth
57
Internal Services – Transitioning to VPN - Should have Auth
URL
Tier 2
In scope

In-Scope Assets and Testing Guidelines

The assets listed in this scope include production services that are currently publicly accessible. Some of these services are planned to become accessible only through our internal network/VPN, while our customer-facing services will remain publicly accessible.

Services transitioning to internal access

Some production services currently accessible from the public Internet are planned to become accessible only through our internal network/VPN.

Some of these services are protected by authentication, while others are intentionally accessible without authentication.

Authenticated services

For services that require authentication, successfully demonstrating that authentication can be bypassed and that the protected application or API can be accessed is sufficient to report a vulnerability.

Researchers are asked not to continue testing beyond the point necessary to demonstrate the authentication bypass. In particular, please do not attempt to access, modify, delete, or extract sensitive data, execute additional privileged functionality, or otherwise disrupt the platform after demonstrating that authentication can be circumvented.

Health, readiness, liveness, monitoring, and other endpoints that are intentionally exposed without authentication are excluded from this requirement.

Unauthenticated services

For services that are intentionally accessible without authentication, the absence of authentication itself is not considered a vulnerability. A report must demonstrate an additional security impact or vulnerability, such as unauthorized access to data or functionality, an authorization bypass, injection, or another security issue.

Customer-Facing Services

Our customer-facing production services will remain publicly accessible and are therefore included in the VDP.

The same testing principles apply to these services:

  • For a service that requires authentication, demonstrating an authentication bypass is sufficient to report a vulnerability.
  • For a service that is intentionally accessible without authentication, the absence of authentication itself is not considered a vulnerability. An additional security impact must be demonstrated.
  • Health, readiness, liveness, monitoring, and other intentionally public endpoints are excluded from this requirement.
  • Researchers must not continue exploitation beyond what is necessary to demonstrate the vulnerability.
  • Researchers must only access data belonging to other users or customers if needed for proof of vulnerability.
  • Researchers must not modify, delete, or extract data belonging to other users or customers.

Account access

Some customer-facing services normally support user account creation. However, account creation is not available for the services covered by this VDP.

Researchers should not attempt to circumvent this restriction or obtain authenticated access through unintended means for the purpose of conducting further testing.

If you require an authenticated account to perform additional testing, or if you would like to investigate the impact of a vulnerability beyond the minimum proof required for this VDP, please request to participate in our separate Intigriti bug bounty program. Additional testing should only be performed within the scope and rules of that program.

Responsible Testing

Our VDP is intended to identify security vulnerabilities while minimizing any potential impact to our production environment.

Once you have demonstrated a vulnerability sufficiently for us to understand and reproduce it, please stop testing. In particular, do not continue exploitation to demonstrate additional impact if doing so could affect the availability, confidentiality, or integrity of our systems or customer data.

If you wish to perform more extensive testing or demonstrate additional impact, please request access to our separate Intigriti bug bounty program.

Out of scope

The following findings and activities are out of scope for this Vulnerability Disclosure Program:

Application

  • WordPress username disclosure.
  • Self-XSS that cannot be used to exploit other users.
  • Verbose error messages, files, or directory listings without disclosure of sensitive information.
  • CORS misconfiguration on non-sensitive endpoints.
  • Missing cookie security flags.
  • Missing security headers.
  • Cross-Site Request Forgery (CSRF) with no or low impact.
  • Presence of the autocomplete attribute on web forms.
  • Reverse tabnabbing.
  • Bypassing rate limits or the absence of rate limits.
  • Best-practice violations such as password complexity, expiration, or reuse policies.
  • Clickjacking without demonstrated impact or requiring unrealistic user interaction.
  • CSV injection.
  • Sessions not being invalidated after logout, enabling 2FA, or similar actions.
  • Tokens leaked to third parties without demonstrated security impact.
  • Email spoofing, SPF, DMARC, or DKIM issues.
  • Content injection without the ability to modify HTML or achieve meaningful impact.
  • Username or email enumeration.
  • Email bombing.
  • HTTP Request Smuggling without demonstrated impact.
  • Homograph attacks.
  • XML-RPC being enabled.
  • Banner grabbing or version disclosure.
  • Failure to strip metadata from files.
  • Same-Site Scripting.
  • Subdomain takeover without successfully taking over the subdomain.
  • Arbitrary file upload without proof that the uploaded file can be accessed or otherwise used.
  • Blind SSRF without demonstrated business impact; pingbacks alone are not sufficient.
  • Disclosed or misconfigured Google Maps API keys without demonstrated security impact.
  • Host header injection without demonstrated business impact.
  • Health, readiness, liveness, monitoring, and similar endpoints that are intentionally exposed without authentication, provided they do not expose sensitive information or functionality.

General

  • Vulnerabilities already known to the company through its own testing or other sources will be treated as duplicates.
  • Theoretical security issues without a realistic exploit scenario or attack surface.
  • Issues requiring complex or unrealistic end-user interaction to exploit.
  • Spam, social engineering, and physical intrusion.
  • Denial-of-Service (DoS), Distributed Denial-of-Service (DDoS), or brute-force attacks.
  • Vulnerabilities that only affect software or components that no longer receive security updates.
  • Attacks requiring physical access to a victim's device, a man-in-the-middle position, or a compromised user account.
  • Recently discovered zero-day vulnerabilities reported within 14 days after the public release of a patch or mitigation may be reported but are generally not eligible for a bounty.
  • Reports stating that software is outdated or vulnerable without a proof of concept.
  • Further exploitation beyond what is necessary to demonstrate an authentication bypass or other vulnerability, including accessing, modifying, deleting, or extracting sensitive data.
  • Testing intended to cause damage, disruption, or degradation of production services.
  • Attempting to obtain or create authenticated accounts on services where account creation is not available through this VDP.
  • Testing that requires authenticated access or extended exploitation beyond the limitations of this VDP; researchers should request access to the separate Intigriti bug bounty program for such testing.

Mobile

  • Shared links leaked through the system clipboard.
  • URIs leaked because a malicious application has permission to view opened URIs.
  • Absence of certificate pinning.
  • Sensitive data in URLs or request bodies when protected by TLS.
  • Lack of application obfuscation.
  • Path disclosure in the application binary.
  • Lack of jailbreak or root detection.
  • Crashes caused by malformed URL schemes.
  • Lack of binary protection or anti-debugging controls, including mobile SSL pinning issues.
  • Snapshot or pasteboard leakage.
  • Runtime hacking exploits that are only possible on jailbroken or rooted devices.
  • API key leakage used only for non-sensitive activities or actions.
Severity assessment

This program follows Intigriti's triage standards based on the proof of concept.

FAQ

Where can we get credentials for the app?
No credentials need to be used. If you want to work with credential, you can please a request to join our intigriti bug bounty program.

All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.

Overall stats
submissions received
4
average payout
N/A
accepted submissions
N/A
total payouts
N/A
Activity
10/1
logo
0xl7r
created a submission
10/1
logo
hackersrinu
created a submission
10/1
logo
makop
created a submission
10/1
logo
onevilx
created a submission
10/1
mateco updated the confidentiality level to public
10/1
mateco updated the confidentiality level to registered
10/1
mateco updated the confidentiality level to application
10/1
Mateco VDP
launched