CompTIA | Synack
CompTIA Vulnerability Disclosure
Protect CompTIA by reporting security vulnerabilities through our Vulnerability Disclosure Program (VDP). Submit findings securely and support a transparent, proactive security process.
To ensure you are testing within current boundaries, please check for periodic updates to our scope as our program evolves. Note that what was approved 3 months ago might not be approved today, due to updates on our infrastructure.
Vulnerabilities submitted to the Program through the form provided will be reviewed by Synack, Inc. (“Synack”). Submissions will be reviewed to confirm they are within the Program scope and a valid security issue. If you submit a valid vulnerability, you will be notified after a fix has been issued, and you will have the opportunity to be added to the Acknowledgments page and to disclose the vulnerability. The submission review and validation process is managed exclusively by Synack through their platform and you must follow the Guidelines, Rules of Engagement, and Scope set forth below to participate. All submissions and queries regarding the Program should be submitted through the Submission Form.
Guidelines
In submitting a request, you agree to:
- Accept and adhere to the Terms of Use.
- Work directly with Synack on vulnerability submissions.
- Provide detailed description of a proof of concept to detail reproduction of vulnerabilities.
- Adhere to these Guidelines and the Rules of Engagement and Scope, and do not engage in disruptive testing like DoS or any action that could impact the confidentiality, integrity or availability of information and systems.
- Do not engage in social engineering or phishing of customers or employees.
- Do not request compensation for time and materials or vulnerabilities discovered.
The following web applications are in scope:
- https://www.comptia.org
- https://shop.comptia.org
- https://platform.comptia.org
- https://login.comptia.org
- https://commerceadmin.testout.com
- comptiassoprodfaadmineus01.azurewebsites.net
- comptiasso-identity-api-prod.azurefd.net
- comptiasso-entitlements-api-prod.azurefd.net
Rules of Engagement
- No Denial of Service testing
- No Physical or Social Engineering
- No testing of Third-party Services
- No Issues that do not affect the latest version of modern browsers
Out of Scope – Low Impact Vulnerabilities
The following vulnerabilities are considered too low of an impact to the client and would be marked as Out of Scope if submitted:
- Google Maps API Keys
- Account/e-mail enumeration using brute-force attacks
- Any low impact issues related to session management (i.e. concurrent sessions, session expiration, password reset/change log out, etc.)
- Bypassing content restrictions in uploading a file without proving the file was received
- Clickjacking/UI redressing
I. Overview
The following terms of use (the “Terms of Use”) apply when you view or use a Responsible Disclosure Program hosted by Synack, Inc. You agree to fully comply with and be bound by the Terms of Use. Please review them carefully.
II. Privacy Policy
We respect the privacy of our Site visitors. Please refer to our Privacy Policy which explains how we collect, use, and disclose information that pertains to your privacy.
III. Eligibility Requirements
You agree that you will not under any circumstances:
- Cause harm to us, our customers or others;
- Be a resident of, or make your Submission from, a country or region against which the United States has issued export sanctions or other trade restrictions;
- Be listed on the U.S. Department of the Treasury’s Specially Designated Nationals List;
IV. Posting and Conduct Restrictions
By transmitting any Submission while using our Site, you agree, represent and warrant as follows:
- If you create an account to view the status of your submission, you are solely responsible for your account and the activity that occurs while signed in to or while using your account.
V. Access Limitation; Appropriate Action
We reserve the right to limit or deny access to our Site and to take other appropriate action if a user violates these Terms of Use.
VI. License Grant
By transmitting your submission to a Responsible Disclosure Program, you perpetually allow us and our affiliates the unconditional ability to use, modify, create derivative work from, distribute, disclose and store the information provided in your Submission.
VII. Intellectual Property
You acknowledge and agree that we retain ownership of all intellectual property rights of any kind related to our Site.
VIII. Disclaimer; Limitation of Damages; Release
OUR SITE IS PROVIDED “AS IS” WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED.
IX. Confidentiality
Any information you receive or collect about us or any of our customers through the Responsible Disclosure Program (“Confidential Information”) must be kept confidential and only used in connection with the Responsible Disclosure Program.
X. Indemnity
You agree to defend, indemnify and hold harmless us and our customers from and against any and all claims, damages, obligations, losses, liabilities, costs or debt, arising from your use of and access to our Site.
XI. Modifications of Terms of Use
We can amend these Terms of Use at any time and will update these Terms of Use upon any amendments.
XII. Applicable Laws; Venue
These Terms of Use and your use of our Site are governed by the laws of the State of California.
XIII. Suggestions and Feedback
We welcome your feedback and inquiries. If you have any comments or questions, please contact us by sending an email to support@synack.com.