Description

Stravito is a knowledge management solution that democratizes access to market research and insights, making it fast and easy to use research to make better decisions. We welcome feedback from security researchers and the general public to help improve our security. If you believe you have discovered a vulnerability, privacy issue, exposed data, or other security issues in any of our assets, we want to hear from you.

Bounties

This is a responsible disclosure program without bounties.

Rules of engagement
Not applicable
User-Agent: Intigriti-VDP-<default user-agent>
max. 5 requests /sec
X-Bug-Bounty: Intigriti-VDP

By participating in this program, you agree to:

  • Respect the Community Code of Conduct
  • Respect the Intigriti Terms and Conditions
  • Respect the scope of the program
  • Not discuss or disclose vulnerability information without prior written consent (including PoC's on YouTube and Vimeo)

Validation times
We aim to validate all submissions within the below timelines (once your submission has been verified by Intigriti)

Vulnerability Severity Time to validate
Exceptional 3 Working days
Critical 5 Working days
High 15 Working days
Medium 30 Working days
Low 45 Working days

Working hours = Mo-Fr 9am - 5pm, except Swedish holidays

Check our fix
We offer up to €50 bonus to verify a resolved issue for us (when requested).
This remains at the discretion of Stravito to award.

Domains

Publicly Facing Assets Related to Stravito

No bounty
Other

Researchers are welcome to submit reports on any publicly facing asset(s) attributed to Stravito, except ones explicitly out of scope.

*.stravito.com

Assets that allow end user input (other than login)

Out of scope
Other

Assets that allow input from end users are out of scope, such as:

  • Contact forms
  • Customer support chat
  • Newsletter subscriptions

Stravito branded sites provided by partners or service providers

Other

In some cases we have Stravito branded sites provided by a partner or service provider. Such sites are out of scope.

https://careers.stravito.com/
https://trust.stravito.com/

Severity assessment

This program follows Intigriti's contextual CVSS standard.

Accepted Issues and Severity
When reporting vulnerabilities, please consider attack scenario/exploitability and the security impact of the bug. We may choose not to accept or to modify the severity of submissions in cases where there is no clear exploit chain, these include:

  • "Best Practice" configuration items not part of a functioning exploit chain.
  • Header Issues such as X-Frame-Options, CSP, etc.
  • Cookie Configuration such as Missing "Secure" Flag on non-sensitive cookies or missing HTTPOnly properties.
  • Mail security configurations such as invalid, incomplete, or missing SPF/DKIM/DMARC records.
  • SSL/TLS configurations.
  • Non-Sensitive information disclosures such as software versions, banner identifications, descriptive error messages, descriptive headers (stack traces, application or server errors).
  • Attacks requiring MITM or physical access to a device.
  • Use of vulnerable libraries without an associated working PoC.

However, it is important to note that in some cases a vulnerability's priority will be modified due to its likelihood or impact. In any instance where a vulnerability rating is modified, an explanation will be provided to the researcher - along with the opportunity to make a case for a higher priority.

Please be aware, Stravito uses HubSpot for content management of our public website. We accept vulnerability reports for HubSpot components and configurations, however, in cases where the same component is determined to be vulnerable across multiple HubSpot pages / websites because of the shared codebase, these will be treated as one unique vulnerability with subsequent reports marked as duplicate.

FAQ

How do I report vulnerabilities to Stravito?
Register an account at the Intigriti bug bounty hunting platform here and start reporting vulnerabilities, earning reputation points and possibly more!

Where can I get credentials for the applications?
We currently don’t offer any credentials to in scope of the vulnerability disclosure program.

Feedback
Would you like to help us improve our program or have some feedback to share, please send your anonymous feedback using this form (note that this form will be checked periodically and should not be used for submission or support queries).

All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.