Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

asana

BugcrowdView on Bugcrowd
RawAI Enhanced
10
In Scope
6
Out of Scope

In-Scope Assets (10)

AssetCategoryBountyQuick Links
*.app.asana.comURLNo
Subdomain takeover at *asana.bizOTHERNo-
https://*.asana.bizOTHERNo-
https://app.asana.comURLNo
https://apps.apple.com/us/app/asana-mobile/id489969512IOSNo-
https://asana.comURLNo
https://asana.com/apps?category=made-by-asanaURLNo
https://asana.com/downloadOTHERNo-
https://form.asana.comURLNo
https://play.google.com/store/apps/details?id=com.asana.app&hl=enANDROIDNo
Out-of-Scope Assets (6)
AssetCategoryBounty
Forms that you do not ownOTHERNo
Other subdomains of asana.comURLNo
Social engineering against Asana Support or Asana EmployeesOTHERNo
asana.okta.comURLNo
assets.asana.bizURLNo
jira*.integrations.asana.plusURLNo