Travelers | Synack
Travelers Vulnerability Disclosure
Protect Travelers by reporting security vulnerabilities through our Vulnerability Disclosure Program (VDP). Submit findings securely and support a transparent, proactive security process.
Overview
This Vulnerability Disclosure Program (the “Program”) is for security researchers interested in reporting cybersecurity vulnerabilities. This is intended for cybersecurity vulnerabilities only.
Vulnerabilities submitted to the Program through the form provided will be reviewed by Synack, Inc. (“Synack”). Submissions will be reviewed to confirm they are within the Program scope and a valid security issue. If you submit a valid vulnerability, you will be notified after a fix has been issued, and you will have the opportunity to be added to the Acknowledgments page and to disclose the vulnerability. The submission review and validation process is managed exclusively by Synack through their platform and you must follow the Guidelines, Rules of Engagement, and Scope set forth below to participate. All submissions and queries regarding the Program must be submitted through the Submission Form.
Guidelines
In submitting a request, you agree to:
- Accept and adhere to Synack’s Terms of Use.
- Work directly with Synack on vulnerability submissions.
- Provide detailed description of a proof of concept to detail reproduction of the vulnerability.
- Adhere to these Guidelines and the Rules of Engagement and Scope, and do not engage in disruptive testing like DoS or any action that could impact the confidentiality, integrity or availability of Travelers’ information and systems.
- Not engage in social engineering or phishing of Travelers’ customers or employees.
- Not access or exfiltrate any personal information or sensitive data. If a vulnerability provides unintended access to data, limit the amount of data you access to the minimum required for effectively demonstrating the vulnerability.
- Not request compensation for time and materials or vulnerabilities discovered.
The following web applications are in scope:
- *.travelers.com
Rules of Engagement
- No Denial of Service (DoS) testing
- No Physical or Social Engineering
- No testing of Third-party Services
- No uploading of any vulnerability or client-related content to third-party utilities (e.g. Github, DropBox, YouTube)
- All attack payload data must use professional language
- If able to gain access to a system, accounts, users, or user data, stop at point of recognition and report. Do not dive deeper to determine how much more is accessible.
- The program strictly prohibits submissions from individuals employed by or contracted to perform work for Travelers
Out of Scope – Low Impact Vulnerabilities
The following vulnerabilities are considered too low of an impact to the client and would be marked as Out of Scope if submitted:
- Google Maps API Keys
- Account/e-mail enumeration using brute-force attacks
- Valid user account/email enumeration not requiring brute-force will be considered
- Any low impact issues related to session management (i.e. concurrent sessions, session expiration, password reset/change log out, etc.)
- Bypassing content restrictions in uploading a file without proving the file was received
- Clickjacking/UI redressing
- Client-side application/browser autocomplete or saved password/credentials
- Descriptive or verbose error pages without proof of exploitability or obtaining sensitive information
- Directory structure enumeration (unless the fact reveals exceptionally useful information)
- Incomplete or missing SPF/DMARC/DKIM records
- Issues related to password/credential strength, length, lockouts, or lack of brute-force/rate-limiting protections
- Account compromises (especially admin) as a result of these issues will likely be considered VALID
- Lack of SSL or Mixed content
- Leaking Session Cookies, User Credentials, or other sensitive data will be reviewed on a case by case basis
- If leaking of sensitive data requires MiTM positioning to exploit, it will be considered out of scope
- Login/Logout/Unauthenticated/Low-impact CSRF
- Low impact Information disclosures (including Software version disclosure)
- Missing Cookie flags
- Missing/Enabled HTTP Headers/Methods which do not lead directly to a security vulnerability
- Reflected file download attacks (RFD)
- Self-exploitation (i.e. password reset links or cookie reuse)
- SSL/TLS best practices that do not contain a fully functional proof of concept
- URL/Open Redirection
- Use of a known-vulnerable library which leads to a low-impact vulnerability (i.e. jQuery outdated version leads to low impact XSS)
- Valid bugs or best practice issues that are not directly related to the security posture of the client
- Vulnerabilities affecting users of outdated browsers, plugins or platforms
- Vulnerabilities that allow for the injection of arbitrary text without allowing for hyperlinks, HTML, or JavaScript code to be injected
- Vulnerabilities that require the user/victim to perform extremely unlikely actions (i.e. Self-XSS)
Acknowledgment of Privacy Policy
By using our Sites you are acknowledging the terms of our Privacy Policy and accepting our Terms of Use, and acknowledge our collection, use, disclosure, and retention of your personal information as described in our Privacy Policy.
Suggestions and Feedback
We welcome your feedback and inquiries. If you have any comments or questions, please contact us by sending an email to support@synack.com.
Company Name: Travelers
Website: https://www.travelers.com/
About: We are an insurance company that cares. Travelers takes on the risk and provides the coverage and service you need to help protect the things that are important to you.