{"id":66097,"date":"2024-04-03T16:21:44","date_gmt":"2024-04-03T16:21:44","guid":{"rendered":"https:\/\/devel.www.cpanel.net\/?page_id=66097"},"modified":"2024-05-16T08:54:20","modified_gmt":"2024-05-16T08:54:20","slug":"cpanel-security-bounty-program","status":"publish","type":"page","link":"https:\/\/devel.www.cpanel.net\/cpanel-security-bounty-program\/","title":{"rendered":"cPanel Security Bounty Program"},"content":{"rendered":"\n
In order to show its appreciation for security researchers who follow responsible disclosure principles, cPanel, Inc. is offering a monetary reward program for researchers who provide assistance with identifying and correcting certain Qualifying Vulnerabilities within the scope of this program.<\/p>\n\n\n\n
To be eligible for a bounty under this program, you must be the first to report a Qualifying Vulnerability within the scope of this program. You must also adhere to cPanel\u2019s Responsible Disclosure policy. This means:<\/p>\n\n\n\n
Any design or implementation issue within cPanel & WHM that substantially affects the confidentiality or integrity of user data or the system is likely to be within the scope of this program. Common examples include:<\/p>\n\n\n\n
Although cPanel assesses each report on a case-by-case basis, some reports simply do not qualify for reward. Common examples of reports that typically do not qualify for reward include:<\/p>\n\n\n\n
cPanel strives to address vulnerabilities in a timely and responsible fashion in order to protect our customers from unnecessary risk. We expect researchers to share this goal and maintain full confidentiality of any vulnerabilities they discover until these flaws are fully remediated and responsibly disclosed. Failure to maintain confidentiality with cPanel regarding a vulnerability during the full timeframe required for cPanel to evaluate, fix, and disclose the vulnerability will be considered a breach of trust by the researcher and will result in the loss of any bounty that would otherwise be due for the discovery of the vulnerability.<\/p>\n\n\n\n
cPanel considers ANY public discussion of a vulnerability, even hints at the existence of such a vulnerability, to be a breach of these confidentiality requirements. Further, sharing information regarding a vulnerability with any third-parties during the time required for cPanel to address the vulnerability will also be considered a breach. Failure to maintain confidentiality during the resolution of a vulnerability will result in disqualification of the specific vulnerability disclosed and may result in the reporter being barred from any future rewards under this program.<\/p>\n\n\n\n
Any tax consequences resulting from the payment of a reward are the recipient\u2019s sole responsibility. Depending on the recipient\u2019s country of residency and citizenship, additional restrictions (such as international and local laws) may limit the ability of a reporter to receive a reward or impose additional requirements on cPanel or the reporter. When direct payment is not possible or desired, reporters of qualifying vulnerabilities will be given the option to donate the bounty reward to a non-profit charity of their choosing from a list of eligible charities provided by cPanel.<\/p>\n\n\n\n
cPanel, in its sole discretion, shall determine the eligibility of all submissions and amount of any final reward offered. Additionally, cPanel may discontinue the reward program at any time with or without notice. cPanel, Inc. staff and their family, friends, neighbors, associates, etc., are not eligible to receive any rewards under this program.<\/p>\n\n\n\n
In cases where multiple parties (including cPanel itself) independently discover the same vulnerability, only the first party to discover the vulnerability will be credited for the finding or awarded any bounty under this program.<\/p>\n\n\n\n
cPanel likes to give public recognition to individuals and companies that assist with fixing security vulnerabilities, but understands that some vulnerability reporters do not desire public acknowledgement. If you desire to remain anonymous, meaning no public mention of you or your company, please let us know.<\/p>\n\n\n\n