
Apache Kafka (European Commission - DIGIT)
External Program
Submit bugs directly to this organization


External Program
Submit bugs directly to this organization
This project has been sponsored by the European Commission as part of the EU-Free and Open Source Software Auditing (EU-FOSSA) project designed to improve the security of free software.
This program will be open for submissions for 8 weeks, though rewards may be processed beyond the 8 week period in order to allow for full evaluation of the impact of valid vulnerability reports.
Note: This program has now been extended for a further two months until the 14th of July
While researching, we'd like to ask you to refrain from:
The PoC must work on the master branch of https://github.com/apache/kafka, or the latest build. Older builds are explicitly out of scope.
Check https://github.com/apache/kafka/blob/trunk/README.md to learn how to build the software.
Our rewards are based on the severity of a vulnerability. HackerOne uses CVSS 3.0 (Common Vulnerability Scoring Standard) to calculate severity. We will update the program over time based on feedback, so please give us feedback on any part of the program you think we can improve on.
Our rewards are based on the severity of a vulnerability. HackerOne uses CVSS 3.0 (Common Vulnerability Scoring Standard) to calculate severity. We will update the program over time based on feedback, so please give us feedback on any part of the program you think we can improve on.
A bonus structure is in place from the 14th of June to 14th July 2019
| SEVERITY | CVSS SCORE | REWARD | Temporary Bonus Structure |
|---|---|---|---|
| critical | 9.0 - 10.0 | €7500 | |
| High | 7.0 - 8.9 | €3250 | |
| Medium | 4.0 - 6.9 | €1300 | |
| Low | 0.1 - 3.9 | €325 |
There is a 20% bonus for including a fix in the report, when accepted by the maintainers. Please use the guidelines outlined here: https://kafka.apache.org/contributing
Note: The 20% bonus is calculated off the new bonus structure.
Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
Thank you for helping keep Apache Kafka and our users safe!
If you have any questions or concerns on this Challenge, please contact [email protected].