U.S. Department Of Education | Synack

Department Of Education Vulnerability Disclosure

Protect the U.S. Department of Education by reporting security vulnerabilities through our Vulnerability Disclosure Program (VDP). Submit findings securely and support a transparent, proactive security process.

Overview

This Responsible Disclosure Program (the “Program”) page is for security researchers interested in reporting application security vulnerabilities. This is intended for application security vulnerabilities only.

Vulnerabilities submitted to the Program through the form provided will be reviewed by Synack, Inc. (“Synack”). Submissions will be reviewed to confirm they are within the Program scope and a valid security issue. If you submit a valid vulnerability, you will be notified after a fix has been issued, and you will have the opportunity to be added to the Acknowledgments page and to disclose the vulnerability. The submission review and validation process is managed exclusively by Synack through their platform and you must follow the Guidelines, Rules of Engagement, and Scope set forth below to participate. All submissions and queries regarding the Program should be submitted through the Submission Form.

Guidelines

In submitting a request, you agree to:

Scope

All internet-accessible, public facing, systems or services of the Department are covered within the scope of the VDP.

Rules of Engagement

Out of Scope – Low Impact Vulnerabilities

The following vulnerabilities are considered too low of an impact to the client and would be marked as Out of Scope if submitted:

Additional specific vulnerability types considered out of scope due to low impact:

Company Name

U.S. Department Of Education

Website

https://www.ed.gov

Submit a Vuln

Start Here

By submitting a vulnerability to our responsible disclosure program, you agree to the Terms of Use.