*.mongodb.com/*· criticalAll Evergreen Assets (Excluding staging)· criticalApp Services/Realm· critical— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for MongoDB.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": true,
"average_time_to_bounty_awarded": 686,
"average_time_to_first_program_response": 1,
"average_time_to_report_resolved": 1385,
"handle": "mongodb",
"id": 0,
"managed_program": true,
"name": "MongoDB",
"offers_bounties": true,
"offers_swag": false,
"response_efficiency_percentage": 85,
"submission_state": "open",
"url": "https://hackerone.com/mongodb",
"website": "https://mongodb.com",
"targets": {
"in_scope": [
{
"asset_identifier": "*.mongodb.com/*",
"asset_type": "WILDCARD",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "*.mongodb.com/* is in scope, and includes\nmongodb.com/docs/\nsupport.mongodb.com\nAll others sites that follow that pattern are in-scope. If the site is owned by MongoDB, it is eligible for a bounty. If it’s owned by a 3rd party, it is not eligible for a bounty. This scope is a catch-all for all products not listed individually with the 'Atlas' Prefix, or covered as an Atlas product, listed elsewhere in the scope. \nmongodb.com/community/forums is in scope, but not eligible for a bounty. \n\nfeedback.mongodb.com is out of scope and not eligible for bounty. Please do not test that platform. All bugs should be reported to AHA, not MongoDB. \n\nArtifactory is being deprecated and not eligible for bounty.",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "All Evergreen Assets (Excluding staging)",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "https://github.com/evergreen-ci/evergreen",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "App Services/Realm",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "MongoDB App Services (fka Realm) has been deprecated. ",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Atlas Charts",
"asset_type": "OTHER",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "charts.mongodb.com",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "Atlas Data Federation",
"asset_type": "OTHER",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Atlas Data Federation is embedded into the Atlas Platform. Read more here: \nhttps://www.mongodb.com/products/platform/atlas-data-federation",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "Atlas IAM",
"asset_type": "OTHER",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "account.mongodb.com and other Identity and Access Management bugs within Atlas, regarding Organizations, Projects and permissions. ",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "Atlas Payments/Billing",
"asset_type": "OTHER",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Billing is integrated into the Atlas Platform, read more here: https://www.mongodb.com/docs/atlas/billing/",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "Cluster-To-Cluster sync",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "https://www.mongodb.com/try/download/mongosync",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Compass",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "https://www.mongodb.com/try/download/compass",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Database Tools",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "https://www.mongodb.com/try/download/database-tools",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Drivers",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "These are the following drivers that are in scope: \nAtlas SQL JDBC Driver\nAtlas SQL ODBC Driver\nC\nC++\nGo\nJVM (Java, Scala, Kotlin)\nLibmongocrypt\nNode.js/Typescript\nPHP\nPython\nRuby\nRust\nThe Swift Driver is not in scope and not eligible for bounty.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Enterprise Edition Products and Tools",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Drivers, cloud tools, enterprise cloud and enterprise server",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Jira Projects",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "MongoDB is open-sourced and has publicly visible JIRA tickets. Only report information disclosure issues-- no technical bugs are accepted. Bounty may be varied. ",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "MongoDB Assistant",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "MongoDB Assistant is integrated into Data Explorer and Compass. ",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "MongoDB Atlas",
"asset_type": "OTHER",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Atlas and Atlas Features and Products are in scope and eligible for bounty. \nAtlas IAM, Charts, Data Federation, Payments/Billing, are listed elsewhere in the scope. Other Atlas products not explicitly listed elsewhere in the scope should be submitted here. This includes, but is not limited to Streams, Online Archive, Clusters, and Backup. ",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "MongoDB Community Server",
"asset_type": "OTHER",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Server Community and Server Enterprise are in scope and eligible for bounty. This includes but is not limited to Cloud Manager, Ops Manager, Search, and the Kubernetes Operators. ",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "MongoDB Connectors",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "The Connectors are in scope. This includes\nKafka Connector\nPowerBI Connector\nBI Connector\nSpark Connector\nTableau Connector",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "MongoDB IntelliJ Plugin",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "https://plugins.jetbrains.com/plugin/24377-mongodb",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "MongoDB MCP Server",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "https://github.com/mongodb-js/mongodb-mcp-server",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "MongoDB Owned GitHub Repositories",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Only github.com/mongodb is considered to be eligible for bounty. Other MongoDB owned repositories are in scope, but not eligible for bounty. \nhttps://github.com/mongodb/kingfisher is out of scope and not eligible for bounty.\n",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "MongoDB Partner Integrations",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "https://cloud.mongodb.com/ecosystem\nPartner integrations may be eligible for bounties, depending on the owner of the issue. ",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "MongoDB Shell",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "https://www.mongodb.com/try/download/shell",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "MongoDB Toolchain",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "http://mongodbtoolchain.build.10gen.cc",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "Relational Migrator",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "https://www.mongodb.com/try/download/relational-migrator",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "University Platform",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "learn.mongodb.com is owned by 3rd party and not eligible for bounty",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "VS Code Plugin",
"asset_type": "OTHER",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "https://marketplace.visualstudio.com/items?itemName=mongodb.mongodb-vscode",
"integrity_requirement": null,
"max_severity": "critical"
}
],
"out_of_scope": [
{
"asset_identifier": "voyageai.com",
"asset_type": "URL",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Out of Scope and Ineligible for Bounty \nhttps://www.voyageai.com",
"integrity_requirement": "high",
"max_severity": "none"
}
]
}
}Atlas Charts· criticalAtlas Data Federation· criticalAtlas IAM· criticalAtlas Payments/Billing· criticalCluster-To-Cluster sync· criticalCompass· criticalDatabase Tools· criticalDrivers· criticalEnterprise Edition Products and Tools· criticalJira Projects· criticalMongoDB Assistant· criticalMongoDB Atlas· criticalMongoDB Community Server· criticalMongoDB Connectors· criticalMongoDB IntelliJ Plugin· criticalMongoDB MCP Server· criticalMongoDB Owned GitHub Repositories· criticalMongoDB Partner Integrations· criticalMongoDB Shell· criticalMongoDB Toolchain· criticalRelational Migrator· criticalUniversity Platform· criticalVS Code Plugin· critical