4 ms·
Its out of scope because the scope microsofts bug bounty programm is limited to web applications and endpoints.
by lhoff 6y ago
Its out of scope because the scope microsofts bug bounty programm is limited to web applications and endpoints.
- Closi 6y agoThis certainly isn't something that is listed on their bug bounty page, and would also be a ridiculous limitation in reality considering the scope of Microsoft's services.
- lhoff 6y agoAre we looking at the same page? Here https://www.microsoft.com/en-us/msrc/bounty-microsoft-cloud https://www.microsoft.com/en-us/msrc/bounty-microsoft-cloud is a header "IN-SCOPE DOMAINS AND ENDPOINTS" with alist of domains and that is described with the following: "Only the following domains and endpoints are eligible for bug bounty awards." I couldn't find something that would match the Teams app on general bug bounty website either (https://www.microsoft.com/de-de/msrc/bounty https://www.microsoft.com/de-de/msrc/bounty)
- Closi 6y agoI would assume it would be under the Microsoft office insider bug bounty.
- staticassertion 6y agoHonestly, for a severe finding like this in their product I think they should have: a) Paid out a bonus anyways for the finding (bug bounties do this often, certainly we did at Dropbox) b) Made this scoping issue more explicit somewhere