The Federal Reserve Vulnerability Disclosure | Synack
The Federal Reserve Vulnerability Disclosure Program
Protect The Federal Reserve by reporting security vulnerabilities through our Vulnerability Disclosure Program (VDP). Submit findings securely and support a transparent, proactive security process.
Responsible Disclosure Policy:
This page is for security researchers interested in reporting application security vulnerabilities. This is intended for application security vulnerabilities only.
If you have reported an issue determined to be within program scope, is determined to be a valid security issue, and you have followed program guidelines, your finding will be recognized and you will be allowed to disclose the vulnerability after a fix has been issued. All submissions and queries regarding the Program should be submitted through the Submission Form.
Federal Reserve Disclosure Policy
The Federal Reserve commits to acknowledging disclosed vulnerabilities promptly and working with the security research community to mitigate or remediate weaknesses.
The Federal Reserve asks participating security researchers to:
- Provide the Federal Reserve reasonable time to fix reported issue before disclosing issues to outside parties
- Not publicly disclose vulnerabilities or related details without explicit written authorization from the Federal Reserve
- Not include sensitive or identifying data in any public disclosures
Program Rules
- Avoid mass scanning Federal Reserve domains. Offending IP addresses may be blocked.
- Please provide detailed reports of the process you used and vulnerabilities identified with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue may not be marked as triaged.
- Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.
- When duplicates occur, the Federal Reserve only triages the first report that was received (provided it can be fully reproduced).
- Multiple vulnerabilities caused by one underlying issue will be treated as one valid report.
- Do not engage in social engineering (e.g., phishing, vishing, smashing).
- Avoid violating individual privacy rights, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.
- Do not exploit beyond what is necessary to demonstrate vulnerability presence.
- Avoid accessing content of communications, data, or information on Federal Reserve information systems except to the extent that information directly relates to the vulnerability and is necessary to prove the vulnerability exists.
- Do not store or share non-public data obtained through testing except to the extent necessary to communicate the finding to the Federal Reserve.
- Do not submit a high-volume of low-quality reports.
- If you are uncertain whether to continue testing, please engage with our team at frrd@responsibledisclosure.com
Typical Vulnerabilities Accepted
- OWASP Top 10 vulnerability categories
- Other vulnerabilities with demonstrated impact
Typical Out of Scope
- Theoretical vulnerabilities
- Informational disclosure of non-sensitive data
- Low impact session management issues
- Self XSS (user defined payload)
Responsible Disclosure Guidelines
- Adhere to the Terms of Use of the Program
- Work directly with the contacts of the Program on vulnerability submissions.
- Provide detailed description of a proof of concept to detail reproduction of vulnerabilities
- Do not engage in disruptive testing like DoS or any action that could impact the confidentiality, integrity or availability of information and systems
- Do not engage in social engineering or phishing of customers or employees
- Do not request compensation for time and materials or vulnerabilities discovered
Safe Harbor
We understand the reluctance some researchers have to share information about vulnerabilities they find because of the potential for criminal or civil liability. To encourage responsible research and disclosure of security vulnerabilities, we do not intend to assert claims under the Computer Fraud and Abuse Act or claims of trespass or similar legal theories against researchers who undertake in good faith to test our systems for vulnerabilities and who bring their findings promptly to our attention. You are expected, as always, to comply with all laws applicable to you and not to disrupt or compromise any data beyond what this VDP permits.
We reserve the right in our sole discretion to determine whether your actions are taken in good faith, are consistent with this policy, or are an inadvertent violation. Please contact us before engaging in conduct that you think may be inconsistent with or unaddressed by this policy. Your efforts to proactively contact us before engaging in any action inconsistent with or unaddressed by this policy will be an important factor in our determination.
Thank you for helping keep the Federal Reserve and our users safe!
Responsible Disclosure Rules of Engagement
- No Denial of Service testing
- No Physical or Social Engineering
- No testing of Third-party Services
- No uploading of any vulnerability or client-related content to third-party utilities (e.g. Github, DropBox, YouTube)
- All attack payload data must use professional language
- If able to gain access to a system, accounts, users, or user data, stop at point of recognition and report. Do not dive deeper to determine how much more is accessible.
- When documenting a vulnerability, if a vulnerability is public, please make sure it is discreet and doesn’t identify the client.
In-Scope Targets
Any publicly-accessible system owned, operated, or controlled by the Federal Reserve System or Federal Reserve Banks, including any Federal Reserve owned web applications or services hosted on those systems.
Federal Reserve Bank sites use non-government top-level domains such as .com, .org, .net, etc.
Federal Reserve Bank domains include, but are not limited to:
- federalreserveonline.org, etc.
- atlantafed.org, etc
- bostonfed.org, etc
- chicagofed.org, etc
- clevelandfed.org, etc.
- dallasfed.org, etc.
- kansascityfed.org, etc.
- minneapolisfed.org, etc.
- newyorkfed.org, etc.
- philadelphiafed.org, etc.
- richmondfed.org, etc.
- sanfranciscofed.org, etc.
- stlouisfed.org, etc.
- federalreserveplazaqa-az.frswebservices.org, etc
- bostonfeduat-az.frswebservices.org, etc
- fedeconjobs.org
- federalreserveplaza.com
- fedpaymentsimprovement.org
- frbservices.us
- federalreserveprocurement.org
- qa.explore.fednow.org
- explore.fednow.org
- frbdiscountwindow.org
- frbservices.org
- chicagofed.org
- chicagopaymentssymposium.org
- clevelandfed.org
- fedcommunities.org
- fedsmallbusiness.org
- moneysmartweekep.org
- oasis-staging.sr.federalreserve.org
- dallasfed.org
- np.login.frsresearch.org
- oasis-uat.sr.federalreserve.org
- np.compute.frsresearch.org
- frsresearch.org
- np.www.frsresearch.org
- np.api.frsresearch.org
- supervisioncentral.org
- moneysmartkc.org
- federalreserveeducation.org
- frbsf.org
- investinwhatsnext.org
- opp-dev.sfeconomicresearch.org
- opp.sfeconomicresearch.org
- ee.econlowdown.org
- econlowdown.org
- content-ee.econlowdown.org
- askthefed.org
- supervisionoutreach.org
- fedinprint.org
- dev.geof.red
- federalreservehistory.org
- frbelection.org
- supervisioncontactsystem.org
- communitybanking.org
- libertystreeteconomics.newyorkfed.org
- fed-mail.org
- qa.markets.newyorkfed.org
- resources.newyorkfed.org
- fed-mail.com
- newyorkfed.org
- surveycentral-test.federalreservesurveys.org
- surveycentral-qa.federalreservesurveys.org
- surveycentral.federalreservesurveys.org
- surveycentral-dev.federalreservesurveys.org
- atlfed.org
- paymentstudy.com
- atlantardc.org
- fedpaymentsmanager.org
- secure.p01.eloqua.com
- fasterpaymenttaskforce.com
- moneysmartweekpartners.org
- fedlineadvantage.net
- frbdiscountwindow.com
- fedreceipt.com
- frsdiscountwindow.org
- frbservice.net
- fedlineconversion.org
- frsdiscountwindow.net
- chicagofedblogs.org
- moneysmartweek.org
- godirect.org
- godirect.org
- dalfrb.appiancloud.com
- dallasfedcomdev.org
- economy-in-action.net
- texascolonias.org
- directoasucuenta.org
- dallasfedcomdev.com
- https://iwms.federalreserve.org/
- federalreserveconsumerhelp.net
- doescollegematter.net
- sffed-education.org
- chairthefed.org
- doescollegematter.org
- twicearound.org
- bankdirectorsdesktop.org
- geof.red
- content-dev.econlowdown.org
- content-qa.econlowdown.org
- qa.federalreservehistory.org
- files.econlowdown.org.s3.amazonaws.com
- files.dev.econlowdown.org.s3.amazonaws.com
- files.content-dev.econlowdown.org.s3.amazonaws.com
- files.content.econlowdown.org.s3.amazonaws.com
- files.content-qa.econlowdown.org.s3.amazonaws.com
- content.econlowdown.org
- economymuseum.com
- myf.red
- files.fraser.stlouisfed.org.s3.amazonaws.com
- files.fraser-qa.stlouisfed.org.s3.amazonaws.com
- files.fred-qa.stlouisfed.org.s3.amazonaws.com
- files.fred-dev.stlouisfed.org.s3.amazonaws.com
- files.fraser-dev.stlouisfed.org.s3.amazonaws.com
- files.research.stlouisfed.org.s3.amazonaws.com
- dev.econlowdown.org
- files.qa.econlowdown.org.s3.amazonaws.com
- m.newyorkfed.org
- nyfedeconomists.org
- frbnyhotline.org
- nyfed.org
- data.newyorkfed.org
- dev.myf.red
Out-of-Scope Targets
This VDP applies to the private sector Federal Reserve Banks (generally .com and .org sites) and not the public sector Federal Reserve Board of Governors (.gov sites).
The following are beyond the scope of this VDP:
- *.gov
- This includes any United States government system, application, or service such as those pertaining to the Federal Reserve Board of Governors or the United States Department of the Treasury
- People, including Federal Reserve employees, contractors, and vendors
- Physical assets, including Federal Reserve property, facilities, and physical security controls
- Federal Reserve Board of Governors
Activities
In-Scope Activities
Activities are limited exclusively to:
- Testing to detect a vulnerability or identify an indicator related to a vulnerability
- Sharing or receiving Federal Reserve information about a vulnerability or an indicator related to a vulnerability
All testing activities should abide by relevant laws
Header identification:
Sometimes abnormal traffic can be considered malicious. Please provide the following header to allow us to correctly identify your traffic:
VDP-Synack-Researcher: username- Also, please append
Synack/usernameto the User Agent String
Out-of-Scope Activities
- Do not harm the Federal Reserve, its customers, employees, or contractors
- Do not intentionally compromise the privacy or safety of Federal Reserve personnel or any third parties
- Do not intentionally compromise the intellectual property or other commercial or financial interests of any Federal Reserve personnel or entities, or any third parties
- Do not exfiltrate or retain any data or sensitive information under any circumstances
- Do not detrimentally compromise/alter, or destroy Federal Reserve or customer data
- Do not perform physical testing
- Do not perform social engineering, including phishing
- Do not perform denial of service testing, including resource exhaustion
- Do not hijack or intentionally disrupt legitimate user sessions
- Do not degrade the quality of Federal Reserve assets, resources, or information
- Do not conduct or initiate fraudulent financial transactions
- Do not perform automated scanning
Vulnerabilities
In-Scope Vulnerabilities
All vulnerabilities are in scope for disclosure excepting those explicitly listed as out-of-scope below.
Out-of-Scope Vulnerabilities
When reporting vulnerabilities, please consider (1) attack scenario / exploitability, and (2) security impact of the bug. The following issues are considered out of scope:
- Clickjacking on pages with no sensitive actions
- Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions
- Attacks requiring Man in the Middle (MITM) or physical access to a user’s device.
- Previously known vulnerable libraries without a working Proof of Concept.
- Comma Separated Values (CSV) injection without demonstrating a vulnerability.
- Missing best practices in SSL/TLS configuration without proof of concept/demonstrating a vulnerability.
- Any activity that could lead to the disruption of service (DoS) for the Federal Reserve
- Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS
- Rate limiting or bruteforce issues on non-authentication endpoints
- Missing best practices in Content Security Policy without demonstrating a vulnerability.
- Missing HttpOnly or Secure flags on cookies not related to authentication or sessions
- Missing email best practices (invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)
- Vulnerabilities only affecting users of outdated or unpatched browsers (More than 2 stable versions behind the latest released stable version)
- Software version disclosure / banner identification issues / descriptive error messages or headers (e.g. stack traces, application or server errors).
- Tabnabbing (persuading users to submit login details and passwords by impersonating a Federal Reserve website)
- Open redirect – unless an additional security impact can be demonstrated
- Issues that require unlikely user interaction unless an additional security impact can be demonstrated
Low Impact Vulnerabilities – Out of Scope
The following vulnerabilities are considered too low of an impact to the client and would be marked as Out of Scope if submitted:
- Google Maps API Keys
- Account/e-mail enumeration using brute-force attacks
- Valid user account/email enumeration not requiring brute-force will be considered
- Any low impact issues related to session management (i.e. concurrent sessions, session expiration, password reset/change log out, etc.)
- Bypassing content restrictions in uploading a file without proving the file was received
- Clickjacking/UI redressing
- Client-side application/browser autocomplete or saved password/credentials
- Descriptive or verbose error pages without proof of exploitability or obtaining sensitive information
- Directory structure enumeration (unless the fact reveals exceptionally useful information)
- Incomplete or missing SPF/DMARC/DKIM records
- Issues related to password/credential strength, length, lockouts, or lack of brute-force/rate-limiting protections
- Account compromises (especially admin) as a result of these issues will likely be considered VALID
- Lack of SSL or Mixed content
- Leaking Session Cookies, User Credentials, or other sensitive data will be reviewed on a case by case basis
- If leaking of sensitive data requires MiTM positioning to exploit, it will be considered out of scope
- Login/Logout/Unauthenticated/Low-impact CSRF
- CSRF Vulnerabilities may be acceptable if they are of higher impact. Examples of low impact CSRF include: Add/Delete from Cart, Add/remove wishlist/favorites, Nonsevere preference options, etc.
- Low impact Information disclosures (including Software version disclosure)
- Missing Cookie flags
- Missing/Enabled HTTP Headers/Methods which do not lead directly to a security vulnerability
- Reflected file download attacks (RFD)
- Self-exploitation (i.e. password reset links or cookie reuse)
- SSL/TLS best practices that do not contain a fully functional proof of concept
- URL/Open Redirection
- Use of a known-vulnerable library which leads to a low-impact vulnerability (i.e. jQuery outdated version leads to low impact XSS)
- Valid bugs or best practice issues that are not directly related to the security posture of the client
- Vulnerabilities affecting users of outdated browsers, plugins or platforms
- Vulnerabilities that allow for the injection of arbitrary text without allowing for hyperlinks, HTML, or JavaScript code to be injected
- Vulnerabilities that require the user/victim to perform extremely unlikely actions (i.e. Self-XSS)
Additional specific vulnerability types considered out of scope due to low impact:
- IIS Tilde File and Directory Disclosure
- SSH Username Enumeration
- WordPress Username Enumeration
- SSL Weak Ciphers/ POODLE / Heartbleed
- CSV Injection
- PHP Info
- Server-Status if it does not reveal sensitive information
- Snoop Info Disclosures
I. Overview
The following terms of use (the “Terms of Use”) apply when you view or use the Responsible Disclosure Program (the “Program”) hosted by Synack, Inc. (“Synack”, “we”, “our”, “us”) on Synack’s website at synack.com (https://www.synack.com/vdp/the-federal-reserve/) (our “Site”). By using our Site, you agree to fully comply with and be bound by the Terms of Use. By using our Site, you agree to fully comply with and be bound by the Terms of Use. Please review them carefully. If you do not accept our Terms of Use, do not access and use our Site. If you have already accessed our Site and do not accept our Terms of Use, you should immediately discontinue use of our Site. Synack commits that, if we conclude, in our sole discretion, that a security vulnerability submitted through the Site complies with the Terms of Use and the applicable Responsible Disclosure Guidelines, Synack will not bring a private action against you or refer the matter for public inquiry
II. Privacy Policy
We respect the privacy of our Site visitors. Please refer to our Privacy Policy which explains how we collect, use, and disclose information that pertains to your privacy. When you access or use the Site, you signify your agreement to this Privacy Policy.
III. Eligibility Requirements
You agree that you will not under any circumstances:
- Cause harm to us, our customers or others;
- Be a resident of, or make your Submission from, a country or region against which the United States has issued export sanctions or other trade restrictions (e.g., Cuba, Iran, North Korea, Sudan, Syria and Crimea);
- Be listed on the U.S. Department of the Treasury’s Specially Designated Nationals List;
- Be in violation of any national, state, or local law or regulation;
- Compromise our privacy or safety or the privacy or safety of our customers (including their customers) and our operation or the operation of our customers’ services;
- Store, share, compromise or destroy our or our customers’ data; or
- Be less than 14 years of age. If you are at least 14 years old, but are considered a minor in your place of residence, you must get your parent’s or legal guardian’s permission prior to participating in the program.
If we discover that you do not meet any of the criteria above, we will remove you from the Program. Any submissions you make to the Program, whether via the Program, in communications regarding an existing ticket for an existing submission , or by email shall be considered “Submission(s)” for purposes of these Terms of Use.
IV. Posting and Conduct Restrictions
By transmitting any Submission while using the Site, you agree, represent and warrant as follows:
- You are solely responsible for your account and the activity that occurs while signed in to or while using your account;
- You will not transmit content that is copyrighted or subject to third party proprietary rights, including privacy, publicity, trade secret, etc., unless you are the owner of such rights or have the appropriate permission from their rightful owner to specifically submit such content to us; and
- You hereby affirm we have the right to determine whether any of your Submissions are appropriate and comply with these Terms of Use, remove any and/or all of your communications, and terminate your account with or without prior notice.
- You will not send unsolicited bulk communications, interfere or attempt to interfere with the proper functioning our or our customers’ websites and systems, and will not publish or link to malicious content intended to damage or disrupt another user’s browser or computer; and
- You will not take any action that we deem to impose or to potentially impose an unreasonable or disproportionately large load on our or our customers’ servers or network infrastructure.
V. Access Limitation; Appropriate Action
We reserve the right, but are not obligated, to limit or deny access to the Site and to take other appropriate action if a user violates these Terms of Use or engages in any activity that violates the rights of any person or entity or which we deem unlawful, offensive, abusive, harmful or malicious.
VI. License Grant
By transmitting your submission to the Program, you perpetually allow us and our affiliates and subsidiaries the unconditional ability to use, modify, create derivative work from, distribute, disclose and store the information provided in your report or to have others do the same on our behalf, and these rights cannot be revoked. You represent that the report is original to you and that you own all right, title and interest in the submission.
VII. Intellectual Property
You acknowledge and agree that we and our licensors retain ownership of all intellectual property rights of any kind related to the Site, including applicable copyrights, trademarks and other proprietary rights. Other product and company names that are mentioned on the Site may be trademarks of their respective owners. We reserve all rights that are not expressly granted to you in the Terms of Use.
VIII. Disclaimer; Limitation of Damages; Release
OUR SITE IS PROVIDED “AS IS” WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING ANY WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, SECURITY, ACCURACY AND NON-INFRINGEMENT. WITHOUT LIMITING THE FOREGOING, WE MAKE NO WARRANTY OR REPRESENTATION THAT ACCESS TO OR OPERATION OF THE SITE WILL BE UNINTERRUPTED OR ERROR FREE. YOU ASSUME FULL RESPONSIBILITY AND RISK OF LOSS RESULTING FROM YOUR DOWNLOADING AND/OR USE OF FILES, INFORMATION, CONTENT OR OTHER MATERIAL OBTAINED FROM THE SITE. TO THE EXTENT PERMITTED BY LAW, IN NO EVENT SHALL WE, OUR AFFILIATES, DIRECTORS, EMPLOYEES OR ITS LICENSORS OR PARTNERS BE LIABLE FOR ANY DIRECT, INDIRECT, PUNITIVE, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR EXEMPLARY DAMAGES, INCLUDING WITHOUT LIMITATION DAMAGES FOR LOSS OF PROFITS, GOODWILL, USE, DATA OR OTHER INTANGIBLE LOSSES, THAT RESULT FROM (A) THE USE, DISCLOSURE, OR DISPLAY OF YOUR INFORMATION OR CONTENT; (B) YOUR USE OR INABILITY TO USE THE SITE; (C) THE SITE GENERALLY OR THE SOFTWARE OR SYSTEMS THAT MAKE THE SITE AVAILABLE; OR (D) ANY OTHER INTERACTIONS WITH THE SITE OR ANY OTHER USER OF THE SITE, WHETHER BASED ON WARRANTY, CONTRACT, TORT (INCLUDING NEGLIGENCE) OR ANY OTHER LEGAL THEORY, WHETHER OR NOT WE HAVE BEEN INFORMED OF THE POSSIBILITY OF SUCH DAMAGE, AND EVEN IF A REMEDY SET FORTH HEREIN IS FOUND TO HAVE FAILED OF ITS ESSENTIAL PURPOSE.
IX. Confidentiality
Any information you receive or collect about us or any of our customers through the Program (“Confidential Information”) must be kept confidential and only used in connection with the ResponsibleDisclosure.com Disclosure Program. You may not use, disclose or distribute any such Confidential Information, including, but not limited to, any information regarding your Submission and information you obtain when researching the sites of our customers, without our prior written consent.
X. Indemnity
You agree to defend, indemnify and hold harmless us, our parent company, officers, directors, employees and agents, from and against any and all claims, damages, obligations, losses, liabilities, costs or debt, and expenses (including but not limited to reasonable attorney’s fees) arising from: (i) your use of and access to the Site; (ii) your violation of any term of these Terms of Use; (iii) your violation of any third party right, including without limitation any copyright, property, or privacy right; or (iv) any claim that any content submitted by you causes damage to a third party. This defense and indemnification obligation will survive these Terms of Use and your use of the Site and the Program.
XI. Modifications of Terms of Use
We can amend these Terms of Use at any time and will update these Terms of Use in the event of any such amendments. It is your sole responsibility to check the Site from time to time to view any such changes. If you continue to access or use the Site, you signify your agreement to our revisions to these Terms of Use.
XII. Applicable Laws; Venue
These Terms of Use and your use of the Site are governed by the federal laws of the United States of America and the laws of the State of California. Any action related to this Site will be filed only in the appropriate state or federal court located within San Mateo County, California. By using this Site, you signify your consent to the jurisdiction of the state and/or federal courts located with San Mateo County, California.
XIII. Suggestions and Feedback
We welcome your feedback and inquiries. If you have any comments or questions, please contact us by sending an email to support@synack.com.
Last updated: January 8, 2025
Company Information
Company Name: The Federal Reserve
Website: https://www.frbservices.org/
About: The Federal Reserve, the central bank of the United States, provides the nation with a safe, flexible, and stable monetary and financial system.