mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 12:27:31 +00:00
Update bug-bounty.mdx
This commit is contained in:
@@ -41,7 +41,7 @@ All final reward amounts are determined at Infisical's discretion based on impac
|
|||||||
|
|
||||||
### Out of Scope
|
### Out of Scope
|
||||||
|
|
||||||
- Social engineering or phishing
|
- Social engineering or phishing (including email hyperlink injection without code execution)
|
||||||
- Rate limiting issues on non-sensitive endpoints
|
- Rate limiting issues on non-sensitive endpoints
|
||||||
- Denial-of-service attacks that require authentication and don't impact core service availability
|
- Denial-of-service attacks that require authentication and don't impact core service availability
|
||||||
- Findings based on outdated or forked code not maintained by the Infisical team
|
- Findings based on outdated or forked code not maintained by the Infisical team
|
||||||
@@ -57,4 +57,4 @@ We ask that researchers:
|
|||||||
- Use testing accounts where possible
|
- Use testing accounts where possible
|
||||||
- Give us a reasonable window to investigate and patch before going public
|
- Give us a reasonable window to investigate and patch before going public
|
||||||
|
|
||||||
Researchers can also spin up our [self-hosted version of Infisical](/self-hosting/overview) to test for vulnerabilities locally.
|
Researchers can also spin up our [self-hosted version of Infisical](/self-hosting/overview) to test for vulnerabilities locally.
|
||||||
|
|||||||
Reference in New Issue
Block a user