Java Component in search.maven.org· criticalJava component NOT in search.maven.org· criticalSuspected Java Component· critical— none listed —
— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Central Security Project.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": false,
"average_time_to_bounty_awarded": null,
"average_time_to_first_program_response": null,
"average_time_to_report_resolved": null,
"handle": "central-security-project",
"id": 0,
"managed_program": false,
"name": "Central Security Project",
"offers_bounties": false,
"offers_swag": false,
"response_efficiency_percentage": 40,
"submission_state": "open",
"url": "https://hackerone.com/central-security-project",
"website": "https://www.sonatype.com/central-security-project",
"targets": {
"in_scope": [
{
"asset_identifier": "Java Component in search.maven.org",
"asset_type": "SOURCE_CODE",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "Use this asset for any component found using the [Central Search](https://search.maven.org) or the [OSS Index Search](https://ossindex.sonatpe.org) for maven components",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "Java component NOT in search.maven.org",
"asset_type": "SOURCE_CODE",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "Use this asset for an open source Java component that could not be found in [search.maven.org](search.maven.org). Our security research team will verify it's a valid open source component available in a public repository. If it is a valid component, we will accept and if it is not a valid component we will let you know. ",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Suspected Java Component",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "Use this if you have a vulnerability that could not be mapped back to a open source project. It was something found in an open source Java application, framework or component from penetration testing or other non source code deterministic testing methodology. \n\n**Note: Only use this if you have a vulnerability but can't identify the vulnerable project** ",
"integrity_requirement": null,
"max_severity": "critical"
}
],
"out_of_scope": []
}
}