From 934f031ed958d3823d797b47e7df49bcee17b273 Mon Sep 17 00:00:00 2001
From: Tom Ritter All bounties paid will be at the discretion of the Mozilla Bounty Committee. The committee will evaluate the severity of reported issues with the help of engineers who work on the affected code. Security researchers are invited to participate in the assignment of ratings, but final decisions on the rating are at the discretion of the Bounty Committee. Typically, the security rating given by the Bounty Committee for a bug must be rated a "sec-high" or "sec-critical" in order for it to be eligible for a bounty. In some circumstances, bounties may be paid for lower-rated bugs as well. (See Security Ratings for details of the rating qualifications.)
+ Typically, the security rating given by the Bounty Committee for a bug must be rated a "sec-high" or "sec-critical" in order for it to be eligible for a bounty. In some circumstances, bounties may be paid for lower-rated bugs as well. (See Security Ratings for details of the rating qualifications.) The bounty for valid potentially exploitable critical and high security rated client security vulnerabilities will be between $20,000 and $3,000 (USD) cash reward, depending on the impact of the vulnerability and the quality of the report, as detailed below. The bounty for a valid, potentially exploitable client security vulnerability rated critical or high is up to $20,000 (USD) cash, depending on the impact of the vulnerability and the quality of the report, as detailed below. The bounty program encourages the earliest possible reporting of potentially exploitable bugs. A bounty is not determined based on the initial submission, but rather on the outcome of the discussion with developers. Improving test cases post-submission, figuring out if an engineer's speculation is founded or not, or other assistance that helps resolve the issue will increase your bounty payout. The bounty program encourages the earliest possible reporting of potentially exploitable bugs. A bounty is not determined based on the initial submission, but rather on the outcome of the discussion with developers. Improving test cases post-submission, figuring out if an engineer's speculation is founded or not, or other assistance that helps resolve the issue can increase your bounty payout. Baseline Report High Quality Report Report Criteria 2UXSS is defined as the ability to execute JavaScript in an arbitrary cross-origin context. As mentioned above, complex user interaction or limited capabilities of the vulnerability (such as requiring a compromised content process; or only being able to inject into a cross-origin domain, but not an arbitrary cross-origin domain) will decrease the bounty award. 3 If precise control of the OOM condition can be demonstrated, this will be considered High Impact. 4 Denial of Service issues that merely crash the browser are not eligible for a bounty. Within Firefox, we have introduced vital security features, exploit mitigations, and defense in depth measures. If you are able to bypass one of these measures, even if you are operating from privileged access within the browser, you are eligible for a bounty. Bounty: Assuming the mitigation is bypassed in a testing scenario, with privileged access, we will treat a bypass of the above listed mitigations as High Impact using the table above, with the same payout range for baseline to high quality report. Bounty: Assuming the mitigation is bypassed in a testing scenario, with privileged access, we will treat a bypass of the above listed mitigations as High Impact using the table above. Bounty Bonus: If the mitigation is bypassed without privileged access, this would count as both a regular security vulnerability eligible for a bounty and a mitigation bypass. The vulnerability payout will be decided per the criteria and table above and the mitigation bypass adds a bonus of an additional 50% of the baseline payout for the category. e.g. a UXSS vulnerability that bypasses our HTML sanitization would earn $8K - $10K plus an additional $4000. Bounty Bonus: If the mitigation is bypassed without privileged access, this would count as both a regular security vulnerability eligible for a bounty and a mitigation bypass. The vulnerability payout will be decided per the criteria and table above and the mitigation bypass adds a bonus of an additional 50% of the payout for the category. For example, a UXSS vulnerability that bypasses our HTML sanitization would earn its UXSS payout of up to $10,000 plus an additional 50%. Note: If you’re in the Bounty Bonus category, you may think submitting them separately could earn you slightly more money than submitting them together. We’re pretty sure that doing so would make the second report bounty-ineligible, but if you think each issue is fully independent, you’re welcome to submit them separately and we’ll consider it.Security Vulnerability Bounty
Rewards Amount
-
-
-
-
-
-
-
-
-
@@ -83,8 +68,7 @@
-
-
-
Rewards Amount
@@ -93,7 +77,6 @@
- High Quality Report
- Baseline: up to
+ Up to
Rewards Amount
Highest Impact
$20,000
- $18,000
@@ -113,7 +96,6 @@ Rewards Amount
Higher Impact
$10,000
- $8,000
@@ -124,50 +106,22 @@ Rewards Amount
-
High Impact - Vulnerabilities not fitting 'Higher' or 'Highest Impact', but still receiving a sec-high rating
+ High Impact
- $5,000
$3,000
-
-
- Typically $3000
-
-
- Moderate Impact, at the discretion of the committee
-
-
- $2,500 - $500
-
-
-
-
-
-
-
-
- Typically $1,500
-
-
-
@@ -178,10 +132,6 @@
-
-
-
-
- Typically $1,000
-
+ Exceptional Moderate Impact vulnerabilities paid at the discretion of the committee
Rewards Amount
Exploit Mitigation Bug Bounty
Exploit Mitigation Bug Bounty
For Developers: Contacting Mozilla
products: