-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 # Thinking you found a security vulnerability? Let's talk and take a responsible disclosure path together. # In a nutshell, we are interested in real vulnerabilities that could substantially affect the confidentiality or # integrity of Back Market's Customers and/or Merchants data, not output of automated scanners. # Following vulnerabilities are examples of vulnerabilities that are *out-of-scope*: # * reports from automated tools or scans # * lack of, or insufficient, rate limiting on an endpoint # * outdated software without any noteworthy vulnerability # * missing security headers which do not lead directly to a vulnerability # * lack of CSRF tokens which do not lead directly to a vulnerability # * missing security best practice which do not lead directly to a vulnerability # When submitting a vulnerability report, please always ensure to provide at least *precise* and detailed steps to # reproduce all described attack scenarios. Additionally, screenshots, samples, scripts, ... are all helpful. # Without precise information, we won't be able to qualify the submission as an exploitable security vulnerability. # Also, please be realistic: bugs requiring exceedingly unlikely user interaction such as entering manually an # attack payload, going through forged third party phishing pages, etc. may realistically not meet the bar. # Due to large amount of emails, we might not be able to respond to all reports for out-of-scope vulnerabilities. Contact: mailto:security@backmarket.com # Sensitive information require adequate protection, and cleartext in email body does not serve that objective. # Therefore, please always encrypt your vulnerability report and provide it as an email attachment. Encryption: https://www.backmarket.com/.well-known/security-pubkey.txt Encryption: https://keys.openpgp.org/search?q=security@backmarket.com Encryption: openpgp4fpr:2cebfa0bd82d37009ab2add25edd605bb8f4c0dd # Back Market is continually looking for new talents, this might be a good opportunity to reach out! Hiring: https://jobs.backmarket.com/ # You know how it works, right? Past the expiration date, consuming info from this file is at your own risk. Expires: Tue, 01 Aug 2023 00:00:00 -0000 -----BEGIN PGP SIGNATURE----- iQJMBAEBCgA2FiEELOv6C9gtNwCasq3SXt1gW7j0wN0FAmLu97oYHHNlY3VyaXR5 QGJhY2ttYXJrZXQuY29tAAoJEF7dYFu49MDdDosQAI77qXTGsyB24LP6WNNJ+sdN 7Gealt2nBWO3tkeWk32rL31OcXvLUui9fFYPYsSB+L7x6wylpNJDYW3KqCFL1x4h mPGZTKui4kVCygdjPIm9DCrMIZOLGMoccojdmT1EN6gS4lx/IqRW1zN7i7t+QUtB ntTWF7UDJvrP0B4X5d3hZcaVYVFfUryFN59ELNOYKoogZPDXcUPwrMEjAI7MJ0XK Dr3FWBsMhGuTkL5izmVL0Hw0C+7G3b1MN5J3oyskgEMarEYHDWB3UP/R68ZCsPC4 h8KVJuD6WDy6KAk/47bMw0UFhd5miME569CFdKoKe4redpcibXzoUEmOACRJUeXZ 65n9PyaPSP7gF3hGOwRVECEX12nMweMhTA3rehOmJ0GaaYKHvHs+sl1sDtGKAhRO Aw/3iJltz4/z6D9en6iAPg4l1J8iVhKGovj5NO8BJZaH5uQ1s7W5WAVDx5+tuiip CMYheA8RudSr5hAl8uGdiTvDoLjjCaWgkncyawlsY2qRxRI8PGEM9pv/GJxCj1UI PyDjRh/jDbsk4t6pt0g4UON+QFaXethgzpO/4qpatHbB8l5eMswd+mS10KQi1CRq xswN4WzfElGfPLUXZdwyF5Oqoxalm6qky5N7JEAcVZCcD+aqCjfiZV/+cZyIxuBH o4RNznHyashJmyRzXAlN =7XAB -----END PGP SIGNATURE-----