Other Hy-Vee owned asset— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Hy-Vee.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": false,
"average_time_to_bounty_awarded": null,
"average_time_to_first_program_response": 2,
"average_time_to_report_resolved": null,
"handle": "hy-vee",
"id": 0,
"managed_program": true,
"name": "Hy-Vee",
"offers_bounties": false,
"offers_swag": false,
"response_efficiency_percentage": 100,
"submission_state": "open",
"url": "https://hackerone.com/hy-vee",
"website": "http://hy-vee.com",
"targets": {
"in_scope": [
{
"asset_identifier": "*.hy-vee.cloud",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "*.hy-vee.com",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "1) In order to register, navigate to \nhttps://www.hy-vee.com/\n\n2) Click on the Log In button\n\n3) Click on \"Create an account\"\n\n4) Fill out the form\ncreate a test account using your @ wearehackerone.com email\n\n5) Click on \"Create Account\".",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Other Hy-Vee owned asset",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "If you believe you have found a vulnerability on an application owned by Hy-Vee other than *.hy-vee.com or *.hy-vee.cloud, you may safely report it to us here on our Vulnerability Disclosure Program. Thank you!",
"integrity_requirement": null,
"max_severity": "critical"
}
],
"out_of_scope": []
}
}— none listed —