— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Spacelift VDP.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
first indexed
30d ago · 3 in-scope assets
// only one snapshot on record — changes appear from the next ingest onward
{
"id": "8148a041-c41d-4128-8c73-f4727002515e",
"url": "https://www.intigriti.com/programs/spacelift/spaceliftvdp/detail",
"name": "Spacelift VDP",
"handle": "spaceliftvdp",
"status": "open",
"targets": {
"in_scope": [
{
"type": "wildcard",
"impact": "Tier 2",
"endpoint": "*.app.spacelift.dev",
"description": "Wildcard covering all per-account subdomains of the Spacelift app (e.g. `<account>.app.spacelift.dev`). This is where the core product lives: authentication and SSO, role-based access control (RBAC), stacks and runs, VCS integrations (GitHub, GitLab, Bitbucket, Azure DevOps), cloud provider integrations (AWS, GCP, Azure), and the REST/GraphQL API. Highest-value areas: tenant isolation, authorization/RBAC bypass, IDOR across accounts, and the cloud-integration confused-deputy scenario."
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "app.spacelift.dev",
"description": "The application's root entry point: login, signup, and the account-agnostic parts of the dashboard. Same environment and rules as the wildcard above; the wildcard does not cover this apex host, which is why it's listed separately."
},
{
"type": "url",
"impact": null,
"endpoint": "spacelift.dev",
"description": "It's a landing page serving mostly static content, and it's also where users can sign up for an account."
}
],
"out_of_scope": []
},
"max_bounty": {
"value": 0,
"currency": "USD"
},
"min_bounty": {
"value": 0,
"currency": "USD"
},
"tacRequired": false,
"company_handle": "spacelift",
"twoFactorRequired": false,
"confidentiality_level": "public"
}— none listed —