什么是银屑病| 牙齿黄是什么原因造成的| 酒石酸是什么| 减肥为什么让早上空腹喝咖啡| 去医院看舌头挂什么科| 炎字五行属什么| 清肺热用什么泡水喝比较好| it是什么意思| 灵犀是什么意思| ca医学上是什么意思| 毛囊炎是什么症状| 人比黄花瘦是什么意思| 肌肉拉伤吃什么药| 犬瘟是什么原因引起的| 卧榻是什么意思| 肥皂剧是什么意思| 抖腿是什么原因| 肺部拍片挂什么科| 七手八脚是什么意思| 雪里红是什么| 痔疮吃什么水果好得快| 什么叫多巴胺| 老烂腿用什么药最好| 炼乳是什么东西| 勖是什么意思| 心肌炎是什么| 什么宽带网速快又便宜| 身上长白色的斑点是什么原因| 糖尿病人可以吃什么| 机械键盘什么轴最好| 进产房吃什么补充体力| 福禄双全是什么意思| 瓜蒌根为什么叫天花粉| 孕妇查凝血是检查什么| 血脂挂什么科| 百雀羚属于什么档次| 油条吃多了有什么危害| 痛风能吃什么菜谱大全| oa是什么意思| 谷氨酸钠是什么添加剂| 性早熟有什么症状| 狒狒是什么动物| 劈腿是什么意思| 皮试是什么意思| 因加一笔是什么字| 8月11是什么星座| 鱼油什么时候吃| cst是什么时间| 辛未日五行属什么| 什么叫认知能力| 996是什么| 新疆在古代叫什么| 3n是什么意思| 血小板低看什么科| 520和521的区别是什么| 拉姆什么意思| 阑尾是什么器官| 无偿献血证有什么用| 物以类聚是什么意思| 婴儿八个月可以吃什么辅食| 西湖醋鱼用什么鱼| 木加一笔变成什么字| 短pr间期是什么意思| 执拗是什么意思| 健脾胃吃什么食物好| 健脾去湿吃什么药| 什么人容易得白血病| 活水是什么意思| 体寒的人吃什么食物好| 什么情况下做肠镜| 癔症是什么意思| 奔是什么生肖| 洗牙为什么要验血| 天神是什么意思| 咏柳的咏是什么意思| 为什么肚子总是胀胀的| 久负盛名的负是什么意思| 最近有什么病毒感染| 什么是蛀牙| 什么病会通过唾液传播| 人吸了甲醛有什么症状| 樵夫是什么生肖| 9月19号什么星座| 医联体是什么意思| 发烧可以吃什么| 水鸭是什么鸭| 大姨妈来的少是什么原因| 指甲长的快是什么原因| 经常喝苏打水有什么好处和坏处| 血糖有点高吃什么食物好| 流连忘返的返是什么意思| 磨牙缺什么| 三点水的字有什么| 什么思而行| 牙结石有什么危害| 斑鸠吃什么| 排卵试纸什么时候测最准确| 1RM什么意思| 不行是什么意思| 脂肪是什么组织| bg什么意思| h1什么意思| 鲻鱼是什么鱼| 验血肝功能看什么指标| 芈月是秦始皇什么人| 人几读什么| 有恙是什么意思| 10月11是什么星座| 麦子什么时候成熟| 咬肌疼是什么原因| 风热咳嗽吃什么药| 白细胞和淋巴细胞偏高是什么原因| 打猎是什么意思| 一什么荷花| 煤油对人体有什么危害| 耳朵烧是什么原因| 逢九年应该注意什么有什么禁忌| 尿道口红肿是什么原因| 虾仁炒什么好吃又简单| 神经元特异性烯醇化酶是什么意思| 三七粉吃了有什么好处| 开车是什么意思| 地奥心血康软胶囊主治什么病| 肚子里面跳动是什么原因| 雅号是什么意思| 蜘蛛的血是什么颜色的| 墨绿色大便是什么原因| 49岁属什么| 994是什么意思| 孕期血糖高可以吃什么水果| 身体抱恙是什么意思| 血肌酐低是什么原因| 眼睛黑色部分叫什么| 为什么会得扁平疣| 头疼去医院挂什么科| 女生的隐私部位长什么样| 康宽杀虫剂能杀什么虫| 关羽使用的武器是什么| 梦见老公怀孕什么预兆| 菊花和金银花一起泡水有什么效果| c3c4补体是什么意思| 沙加女是什么字| rh是什么单位| 树懒是什么动物| 肋软骨炎吃什么药最好| 榴莲树长什么样子图片| 高血糖挂什么科室的号| 维c有什么功效和作用| 烩是什么意思| 急得什么| 空调嗡嗡响是什么原因| 4月6号什么星座| 增强抵抗力免疫力吃什么| 獭尾肝是什么意思| 尿道炎用什么药治疗| 耐力板是什么材质| 开什么节什么的成语| 培根是什么| 肉质瘤是什么东西| 专科女生学什么专业好| 琪五行属性是什么| 什么贝壳| 为什么医院不建议药流| 孕早期吃什么水果好| 双子男喜欢什么样的女生| 即兴表演是什么意思| 玄色是什么颜色| 河蚌吃什么食物| 芒果什么人不能吃| 肠镜检查挂什么科室| 小儿厌食吃什么药最好| 验血能查出什么| 梦见吃药是什么意思| 氢化油是什么东西| 激素六项主要是查什么| 道什么意思| 低钠盐适合什么人吃| 瘢痕子宫是什么意思| 黎明是什么时候| 落子是什么意思| 哮喘不能吃什么| 腺病是什么意思| 山东人喜欢吃什么| 除了胃镜还有什么检查胃的方法吗| 半夜两点是什么时辰| 1997年属牛的是什么命| 工装裤搭配什么上衣| 农历六月初四是什么日子| 做梦坐飞机是什么意思| 1889年属什么生肖| 宝宝拉肚子吃什么| 什么的奇观| 耳石症看什么科| 心衰病人吃什么食物好| 布病是什么| 什么样的红点是白血病| 经期吃芒果有什么影响| 念珠菌吃什么药最好| 灸石门为什么会不孕| 吃什么东西越吃越饿| 3p 什么意思| 透骨草长什么样| 一什么面包| 这是什么电影| 苑什么意思| 泌尿科主要看什么病| 风寒感冒吃什么| 欲代表什么生肖| 天空像什么| 平躺就咳嗽是什么原因| 处女座是什么象| 芹菜不能和什么食物一起吃| 手串19颗代表什么意思| 坐骨神经痛吃什么药好得快| 血糖高吃什么可以降下来| 疱疹吃什么药见效快| 什么照片看不出照的是谁| 心衰竭是什么病严重吗| 着凉吃什么药| 喉咙有烧灼感吃什么药| 白细胞酯酶弱阳性是什么意思| 叕什么意思| 大便泡沫状是什么原因| 法是什么| 玉字是什么结构| lg手机是什么牌子| 凌晨的凌是什么意思| 奶嚼口是什么| 黄疸是什么样子的图片| 肠脂膜炎是什么病严重吗| 气性坏疽是什么病| 分心念什么| 水平是什么意思| 豆浆不能和什么一起吃| 女性绝经前有什么症状| 土生土长是什么生肖| 骨折吃什么药好得快| 为什么打哈欠会传染| 玉髓是什么玉| 壬水命是什么意思| icp是什么意思| 三白眼是什么意思| 转铁蛋白阳性什么意思| 出佛身血是什么意思| 5羟色胺是什么| 子宫肌瘤是什么原因导致的| 眼睛发炎用什么药效果好| 胆囊小是什么原因| 梦到刷牙什么意思| 心口疼挂什么科| 白是什么意思| 消化不好吃什么药最好| 肝血不足吃什么药| AT代表什么| 什么是iga肾病| 宜家宜室什么意思| 什么时候同房容易怀孕| 粉领是什么意思| 出家人不打诳语是什么意思| 结膜炎用什么眼药水好| 博士的学位是什么| 超声检查是什么| 晚上10点是什么时辰| 1222是什么星座| 百度
ANNOUNCEMENTVoyage AI joins MongoDB to power more accurate and trustworthy AI applications on Atlas. Learn more >
NEWMongoDB 8.0: Experience unmatched speed and performance. Check it out >
AnnouncementMongoDB 8.0: Experience unmatched speed and performance. Check it out >

[中国电影报道]吴亦凡:“精准扶贫”之我见

MongoDB takes the security of its products and services seriously. Individuals who identify a potential security vulnerability are encouraged to report it promptly through MongoDB’s bug bounty program.

Coordinated Disclosure

百度 这是我们党经受住执政考验的道义支撑和根本价值取向。

MongoDB is committed to the security of its products and the protection of customer data. Security researchers, customers, and partners are encouraged to report potential vulnerabilities or incidents related to MongoDB products to help ensure timely resolution.

MongoDB operates a bug bounty program through HackerOne, where eligible security researchers may receive monetary rewards for valid vulnerability reports. MongoDB’s security team reviews and validates all submissions in accordance with the company’s Vulnerability Disclosure Policy.

Further details on submitting a vulnerability report, including the current scope and rewards, can be found on the HackerOne program page.

For those who prefer not to participate in the bug bounty program, security vulnerabilities can also be submitted directly via the security bug form.

Program Scope

Security bugs or vulnerabilities found on any MongoDB products or tools may be reported via the security bug form. Please refer to the security-related information and configuration guidance below before submitting a new vulnerability.

The scope of MongoDB’s bug bounty program is MongoDB Owned Domains, MongoDB Free Tier Atlas, and a few MongoDB Shipped Products with exceptions (please refer to the Out of Scope section). For a detailed list of our scopes, please refer to the HackerOne program page. When submitting a report, if the asset involved is not explicitly called out in scope, it will not be eligible for bounty.

If the vulnerability falls outside of this immediate scope, you are encouraged to submit the vulnerability via MongoDB’s security bug form.

Out of Scope and Non Qualifying Reports

Please note that all evergreen endpoints (including staging) are out of scope of this program and not eligible for bounty.

  • Public Jira Projects: We have multiple Jira Projects that have been intentionally made public. Please only submit Jira-related reports that involve sensitive information disclosure.
  • Subdomain takeovers for out of scope domains
  • Clickjacking on pages with no sensitive actions
  • Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions
  • Attacks requiring MITM or physical access to a user's device
  • Previously known vulnerable libraries without a working Proof of Concept
  • Comma Separated Values (CSV) injection without demonstrating a vulnerability
  • Missing best practices in SSL/TLS configuration
  • Any activity that could lead to the disruption of our service (DoS)
  • Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS
  • Rate limiting or bruteforce issues on non-authentication endpoints
  • Missing best practices in Content Security Policy
  • Missing HttpOnly or Secure flags on cookies
  • Missing email best practices (Invalid, incomplete, or missing SPF/DKIM/DMARC records, etc.)
  • Vulnerabilities only affecting users of outdated or unpatched browsers [Fewer than two stable versions behind the latest released stable version]
  • Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors)
  • Public zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case by case basis
  • Tabnabbing
  • Open redirect; unless an additional security impact can be demonstrated
  • Issues that require unlikely user interaction
  • Artifactory issues
  • Known false positives:
    • Content injection
    • Error Message
    • SCRAM-SHA1 authentication mechanism's login credentials disclosure
    • SPF record configuration on 10gen.com or mongodb.com
    • Server version disclosure
    • Information Disclosure on /secure/QueryComponent!Default.jspa endpoint
  • Accepted Risks:
    • CSRF with minimal security implications i.e. CSRF on logout
    • CSRF Token Leak
    • JavaScript error
  • Good practice settings:
    • CSP uses unsafe-inline, Missing Certificate Authority, Authorization Rule, Missing HSTS, Missing security headers, No X-Frame Options Header on developer.mongodb.com, Open redirect using Host header.
    • No X-Frame Options Header on developer.mongodb.com

Privacy

See MongoDB’s Legal Hub for our Privacy Policy and more information on our privacy program.

Disclosure

MongoDB, Inc. requests that security researchers do not publicly disclose any information regarding the vulnerabilities they discover or exploit the issue until the company has had the opportunity to analyze the vulnerability, to respond to the notification, and to notify key users, customers, and partners.

The amount of time required to validate a reported vulnerability depends on the complexity and severity of the issue. MongoDB, Inc. takes all required security vulnerabilities very seriously and will always ensure that there is a clear and open channel of communication with the reporter. After validating an issue, MongoDB, Inc. coordinates public disclosure of the issue with the reporter in a mutually agreed timeframe and format.

Guidelines

Contact Us

For support, please use the MongoDB Support Hub.

Recognition

MongoDB thanks the following individuals for identifying and assisting in fixing Security related flaws or vulnerabilities in MongoDB products/services via our disclosure process.

ResearcherSocial Media/ContactValid ReportsRecognition Points
Suhas Sunil Gaikwad-110
Mehedi Hasan (SecMiners BD)Facebook18
Pritam MukherjeeLinkedIn18
Bhavya JainTwitter18
Taha Smily-18
David CalligarisTwitter18
Rich Mirch-18
Mitch Wasson of Cisco's Advanced Malware Protection GroupEmail18
Philippe Jacquot-18
Simon Budail-Essard-18
Henri Salo from Nixu Corporation-30
Pankaj Kumar ThakurLinkedIn2*
@SecurityMateTwitter2*
Mohsin KhanLinkedIn2*
Mohd.Danish AbidLinkedIn1*
Dristant UpretyLinkedIn1*
Emad Al-Mousa-1*
Mohammad Hosein Askari-1*
Kyle MartinLinkedIn1*
Abdul Rehman Tariq-1*
Tony Yesudas-1*
Soundar.MLinkedIn1*
Feng Xiao from Georgia Tech-1*
Will AshworthEmail1*
Ketan Madhukar Mukane-1*
Sicheng Liu of Beijing DBSEC Technology Co., Ltd-1*
Arbazz Hussain-1*
Andre Protas of Apple-1*
Vineet KumarEmail1*
Alyssa Herrera-1*
Jamie (James C.) Davis of Virginia Tech-1*
ALI WAMIM KHAN-1*
Nenad Borov?anin-1*
Cameron Dawe-1*
Kamil Sevi-1*
Sumit Sahoo-1*
Richo Healey-1*
Andrea Palazzo (Truel IT)-1*
Kai Lu and Xiaopeng Zhang of Fortinet's FortiGuard Labs-1*
Christian Hansen-1*
Jason King-1*
Daniel Isaac Khan Ramiro-1*
joev@metasploit.com-1*
Florian Gaultier-1*
Gerd Jungbluth-1*
Will Urbanski-1*
Yury Maryshev-1*
Mikhail Firstov-1*
HD Moore-1*
Md. Nur A Alam Dipu-1*
Omar Amin-1*
Hugo Ferrando Seage-1*
Raghotham Mruthike from DeskNineLinkedIn2*

Researcher

Social Media/Contact
Suhas Sunil Gaikwad-
Mehedi Hasan (SecMiners BD)Facebook
Pritam MukherjeeLinkedIn
Bhavya JainTwitter
Taha Smily-
David CalligarisTwitter
Rich Mirch-
Mitch Wasson of Cisco's Advanced Malware Protection GroupEmail
Philippe Jacquot-
Simon Budail-Essard-
Henri Salo from Nixu Corporation-
Pankaj Kumar ThakurLinkedIn
@SecurityMateTwitter
Mohsin KhanLinkedIn
Mohd.Danish AbidLinkedIn
Dristant UpretyLinkedIn
Emad Al-Mousa-
Mohammad Hosein Askari-
Kyle MartinLinkedIn
Abdul Rehman Tariq-
Tony Yesudas-
Soundar.MLinkedIn
Feng Xiao from Georgia Tech-
Will AshworthEmail
Ketan Madhukar Mukane-
Sicheng Liu of Beijing DBSEC Technology Co., Ltd-
Arbazz Hussain-
Andre Protas of Apple-
Vineet KumarEmail
Alyssa Herrera-
Jamie (James C.) Davis of Virginia Tech-
ALI WAMIM KHAN-
Nenad Borov?anin-
Cameron Dawe-
Kamil Sevi-
Sumit Sahoo-
Richo Healey-
Andrea Palazzo (Truel IT)-
Kai Lu and Xiaopeng Zhang of Fortinet's FortiGuard Labs-
Christian Hansen-
Jason King-
Daniel Isaac Khan Ramiro-
joev@metasploit.com-
Florian Gaultier-
Gerd Jungbluth-
Will Urbanski-
Yury Maryshev-
Mikhail Firstov-
HD Moore-
Md. Nur A Alam Dipu-
Omar Amin-
Hugo Ferrando Seage-
Raghotham Mruthike from DeskNineLinkedIn
Valid Reports
Suhas Sunil Gaikwad1
Mehedi Hasan (SecMiners BD)1
Pritam Mukherjee1
Bhavya Jain1
Taha Smily1
David Calligaris1
Rich Mirch1
Mitch Wasson of Cisco's Advanced Malware Protection Group1
Philippe Jacquot1
Simon Budail-Essard1
Henri Salo from Nixu Corporation3
Pankaj Kumar Thakur2
@SecurityMate2
Mohsin Khan2
Mohd.Danish Abid1
Dristant Uprety1
Emad Al-Mousa1
Mohammad Hosein Askari1
Kyle Martin1
Abdul Rehman Tariq1
Tony Yesudas1
Soundar.M1
Feng Xiao from Georgia Tech1
Will Ashworth1
Ketan Madhukar Mukane1
Sicheng Liu of Beijing DBSEC Technology Co., Ltd1
Arbazz Hussain1
Andre Protas of Apple1
Vineet Kumar1
Alyssa Herrera1
Jamie (James C.) Davis of Virginia Tech1
ALI WAMIM KHAN1
Nenad Borov?anin1
Cameron Dawe1
Kamil Sevi1
Sumit Sahoo1
Richo Healey1
Andrea Palazzo (Truel IT)1
Kai Lu and Xiaopeng Zhang of Fortinet's FortiGuard Labs1
Christian Hansen1
Jason King1
Daniel Isaac Khan Ramiro1
joev@metasploit.com1
Florian Gaultier1
Gerd Jungbluth1
Will Urbanski1
Yury Maryshev1
Mikhail Firstov1
HD Moore1
Md. Nur A Alam Dipu1
Omar Amin1
Hugo Ferrando Seage1
Raghotham Mruthike from DeskNine2
Recognition Points
Suhas Sunil Gaikwad10
Mehedi Hasan (SecMiners BD)8
Pritam Mukherjee8
Bhavya Jain8
Taha Smily8
David Calligaris8
Rich Mirch8
Mitch Wasson of Cisco's Advanced Malware Protection Group8
Philippe Jacquot8
Simon Budail-Essard8
Henri Salo from Nixu Corporation0
Pankaj Kumar Thakur*
@SecurityMate*
Mohsin Khan*
Mohd.Danish Abid*
Dristant Uprety*
Emad Al-Mousa*
Mohammad Hosein Askari*
Kyle Martin*
Abdul Rehman Tariq*
Tony Yesudas*
Soundar.M*
Feng Xiao from Georgia Tech*
Will Ashworth*
Ketan Madhukar Mukane*
Sicheng Liu of Beijing DBSEC Technology Co., Ltd*
Arbazz Hussain*
Andre Protas of Apple*
Vineet Kumar*
Alyssa Herrera*
Jamie (James C.) Davis of Virginia Tech*
ALI WAMIM KHAN*
Nenad Borov?anin*
Cameron Dawe*
Kamil Sevi*
Sumit Sahoo*
Richo Healey*
Andrea Palazzo (Truel IT)*
Kai Lu and Xiaopeng Zhang of Fortinet's FortiGuard Labs*
Christian Hansen*
Jason King*
Daniel Isaac Khan Ramiro*
joev@metasploit.com*
Florian Gaultier*
Gerd Jungbluth*
Will Urbanski*
Yury Maryshev*
Mikhail Firstov*
HD Moore*
Md. Nur A Alam Dipu*
Omar Amin*
Hugo Ferrando Seage*
Raghotham Mruthike from DeskNine*
* These reporters were added to the hall of fame prior to the new revamped policy.
百度