Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

okta

BugcrowdView on Bugcrowd
RawAI Enhanced
22
In Scope
17
Out of Scope

In-Scope Assets (22)

AssetCategoryBountyQuick Links
Desktop MFA for WindowsOTHERNo-
Desktop MFA for macOSOTHERNo-
Okta On-Prem Agents ( AD, LDAP, RDP, IWA )OTHERNo-
Okta Verify (Windows)OTHERNo-
Password Sync for macOSOTHERNo-
bugcrowd-pam-###.oktapreview.comURLNo
bugcrowd-pam-###.pam.oktapreview.comURLNo
http://app.scaleft.com/URLNo
https://apps.apple.com/us/app/okta-verify/id490179405OTHERNo-
https://apps.apple.com/us/app/okta-verify/id490179405IOSNo-
https://bugcrowd-pam-###-admin.oktapreview.comURLNo
https://bugcrowd-pam-###.at.oktapreview.comURLNo
https://bugcrowd-pam-###.oktapreview.comURLNo
https://bugcrowd-pam-###.workflows.oktapreview.comURLNo
https://help.okta.com/asa/en-us/Content/Topics/Adv_Server_Access/docs/client.htmOTHERNo-
https://help.okta.com/en/prod/Content/Topics/Adv_Server_Access/docs/sftd-windows.htmOTHERNo-
https://help.okta.com/en/prod/Content/Topics/Settings/download-browser-plugin.htmOTHERNo-
https://play.google.com/store/apps/details?id=com.okta.android.auth&hl=en_US&gl=USANDROIDNo
https://support.okta.comURLNo
https://www.okta.com/fastpass/OTHERNo-
https://www.okta.com/products/advanced-server-access/URLNo
personal.trexcloud.comURLNo
Out-of-Scope Assets (17)
AssetCategoryBounty
*.okta.comURLNo
*.trexcloud.comURLNo
Anything not explicitly called out above as in-scopeOTHERNo
AtSpoke - Entitlement bundles as a resource in access requestsURLNo
AtSpoke - Okta Workflows actions in access requestsURLNo
Backend Okta non-app infrastructureOTHERNo
Network layer issuesOTHERNo
bugcrowd-%username%-1.oktapreview.comURLNo
bugcrowd-%username%-2.oktapreview.comURLNo
developer.okta.comURLNo
https://app.scaleft.com/p/signupURLNo
https://github.com/oktadevURLNo
https://scaleft.comURLNo
login.okta.comURLNo
pages.okta.comURLNo
trust.okta.comURLNo
www.okta.com (static site)URLNo