
Republik AG
Bounty Range
$62 - $3,720
external program
«Republik» is a digital magazine for politics, business, society and culture. It is a service for interested people in a complex world. We research, ask questions, classify and uncover. And provide you with facts and contexts as a basis for your own reflections and decisions.
«Republik» is financed by its more than 28,000 subscribers. We are owned by no one - but a little bit by each of our members. Together we are a rebellion against the media corporations and for media diversity.
«Republik» is completely free of advertising. We disclose everything: our finances, working methods, mistakes, salaries - because we are convinced that transparency is important. Our code base is open source, targets listed below point to the relevant repositories
Republik AG operates various services (platforms, services). Only services from explicitly listed domains / URLs are in the scope of the Bug Bounty Program. All other domains or explicitly listed services are therefore not eligible for reward and do not fall under the Legal Safe Harbor Agreement.
By participating in this Bug Bounty Program, Friendly Hackers undertake to document information about any vulnerability found exclusively via the platform's designated reporting form and not in any other places. They also agree to keep the found vulnerability secret for 90 days after reporting it on the platform. Finally, they undertake to upload to the platform any data from customers that they have obtained as part of a bug bounty program and to delete any local copies afterwards and not to distribute them further.
In participating in the program, ethical hackers agree not to use methods that would adversely affect the tested applications or their users. These include:
In addition to the prohibited hacking methods listed above, Friendly Hackers are required to immediately discontinue vulnerability scanning if they determine that their conduct will result in a significant degradation (negative impact on regular users or on the operations team) of the Platform's or Service's operations.
The classification is verified using the Common Vulnerability Scoring System (CVSS, see first.org).
Any design or implementation problem can be reported that is reproducible and affects security.
Typical examples:
Other examples:
The following vulnerabilities and forms of documentation are generally not wanted and will be rejected:
The program is suspended when the set cost limit is reached.
The following services and applications may be tested. All other targets and third party services not listed here are not in scope. Especially Metabase, Matomo, Stripe, PayPal, PostFinance, Mailchimp, Mandrill and other 3rd party software not in scope. If not listed otherwise source code can be found at https://github.com/republik/plattform.
The organisation gives their approval for Friendly Hackers to use hacking methods based on the specified bug bounty program. Due to this consent, the criminal liability criterion of unauthorized use and thus the criminal liability of the Friendly Hackers with regard to the elements of crime in Art. 143 StGB (unauthorized data acquisition) and Art. 143bis StGB (unauthorized intrusion into a data processing system) does not apply.
| Severity | Bounty |
|---|---|
| Critical | CHF 1500-3000 |
| High | CHF 800-1500 |
| Medium | CHF 200-800 |
| Low | CHF 50-200 |