HomeSecurityGitHub bug bounty: Researchers' rewards reach $1.5 million

GitHub bug bounty: Researchers' rewards reach $1.5 million

Over half a million dollars have been awarded in rewards to security researchers participating in GitHub's bug bounty program over the past year, bringing the total to $1.5 million.

See also: Hacker won $2 million in bug bounty programs!

GitHub bug bounty

GitHub has been running the GitHub Security Bug Bounty program for seven years.

Bug bounty programs are now very popular and more and more companies and services are asking security researchers to scan their systems for potential vulnerabilities, for a fee.

“From February 2020 to February 2021, we handled the highest volume of reports than any previous year,” GitHub says.

A total of 1,066 bug reportsover the past year to GitHub's public and private programs (the latter focusing on betas and other products that haven't been released yet). It also awarded $524,250 for 203 vulnerabilities. Since GitHub launched its public program on HackerOne, the rewards have now reached $1,552,004.

See also: GitHub: Developers will upload videos to their repositories

The scope of GitHub's bug bounty program includes many GitHub-owned domains and other assets, such as the GitHub API, Actions, Pages, and Gist. Reporting critical vulnerabilities (e.g., those that allow code execution, SQL attacks, and login bypass) can earn researchers up to $30,000.

GitHub bug bounty: Researchers' rewards reach $1.5 million

GitHub also operates under the Safe Harbor, which says that bug hunters who disclose vulnerabilities responsibly and in accordance with company policies are protected from potential legal consequences of their research.

The company also said that over the past year, an open redirect vulnerability has been the platform's "favorite" bug. William Bowling was able to develop an exploit that showed how this vulnerability on GitHub.com could compromise Gist user OAuth flows.

See also: How to quickly and easily delete a GitHub repository?

Bowling managed to earn $10,000 for reporting this particular vulnerability.

GitHub also gained CVE Number Authority (CNA) status in 2020 and has begun issuing CVE IDs for vulnerabilities in GitHub Enterprise Server.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS