avatar
Bug bounty
Public

GOJEK - Public Bounty Program

GoTo Group is the largest digital ecosystem in Indonesia, with a mission to “empower progress” by offering technology infrastructure and solutions that help everyone to access and thrive in the digital economy. GoTo’s ecosystem comprises of on-demand transport, e-commerce, food and grocery delivery, logistics and fulfillment, and financial services through the Gojek, Tokopedia and GoTo Financial platforms.

Reward

Bounty
$5
Low
$50
Medium
$600
High
$1,800
Critical
$3,500

Program

Avg reward
-
Max reward
-

Scopes
16
Supported languages
English

Hacktivity

Reports
931
1st response
< 1 day
Reports last 24h
5
Reports last week
35
Reports this month
52

Gojek

Gojek is rapidly expanding product offerings to our consumers. This growth is a win for everyone, but we want to ensure that our consumers remain safe on our platform. We take the security of our consumers very seriously and are thus taking steps to ensure we work closely with the broader security community to handle responsible disclosure of any bugs found on our platform.

We look forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe.

Program Rules

At Gojek, we recognize the important role that security researchers play in helping to keep Gojek and our customers secure.

By participating in this program you acknowledge that you have read and agreed to the Program Rules, which is defined as this entire document.

Testing Policy and Responsible Disclosure

Please adhere to the following rules while performing research on this program:

  • Denial of service (DoS) attacks on Gojek applications, servers, networks or infrastructure are strictly forbidden.
  • Avoid tests that could cause degradation or interruption of our services.
  • Do not use automated scanners or tools that generate large amount of network traffic.
  • Only perform tests against your own accounts to protect our users' privacy.
  • Do not leak, manipulate, or destroy any user data or files in any of our applications/servers.
  • Do not copy any files from our applications/servers and disclose them.
  • No vulnerability disclosure, full, partial or otherwise, is allowed.
  • Social engineering (e.g. phishing, vishing, smishing) is prohibited.

Reward Eligibility and Amount

We are happy to thank everyone who submits valid reports which help us improve the security of Gojek, however only those that meet the following eligibility requirements may receive a monetary reward:

  • You must be the first reporter of a vulnerability.
  • The vulnerability must be a qualifying vulnerability (see below).
  • Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.
  • The report must contain the following elements:
    • Clear textual description of the vulnerability, how it can be exploited, the security impact it has on the application, its users and Gojek, and remediation advice on fixing the vulnerability
    • Submit one vulnerability per-report, unless you need to chain vulnerabilities to provide impact.
    • Proof of exploitation: screenshots and/or videos demonstrating the exploit was performed, and showing the final impact
    • Provide complete steps with the necessary information to reproduce the exploit, including (if necessary) code snippets, payloads, commands etc
  • You must not break any of the testing policy rules listed above
  • You must not be a former or current employee of Gojek or one of its contractors.
  • We have 30 days delay for a CVE in order to be eligible for reward.

Recent CVE 30 Days Delay

To ensure we have reasonable time to patch recently released Common Vulnerabilities and Exposures (CVEs), any vulnerability based on a CVE released within the last 30 days will not be eligible for a bounty until after this period, This delay allows us to adequately assess, test, and deploy patches for newly disclosed vulnerabilities.

Reward amounts

Reward and amount will be decided based on Gojek Security team discretion. We will give our best to assess the vulnerability and use CVSS scoring and actual business impact of the vulnerability upon performing risk analysis.

Third-Party Services

If you believe an issue with one of our third-party service providers is the result of Gojek’s misconfiguration or insecure usage of that service (or you’ve reported an issue affecting many customers of the service that you believe Gojek can temporarily mitigate without stopping usage of the service while a fix is implemented upstream), we’d appreciate your report regarding the issue.

Keep in mind that any reports regarding third-party services are likely to not be eligible for a reward.

Scope

  • Valid submissions for the assets in the ‘Scope’ section will be rewarded accordingly in this bug bounty program.

  • Please note that we cannot promise you a bounty for valid report submissions that are outside of the in-scope assets. However, in certain exceptional cases, if we decide to reward, the decision will be at our discretion and it won’t probably go higher than a Tier 2 Medium bounty.

Program Owner Discretion

All determinations regarding submitted reports — including but not limited to validity, scope applicability, severity rating, duplicate status, reward eligibility, reward amount, are made solely at the discretion of GoTo Company as the program owner. Researchers acknowledge that GoTo Company's decisions on these matters are final.

In the event of any conflict between this program policy and general guidance provided elsewhere, the rules stated in this program brief apply to participation in this specific program.

Focus Areas

We are happy for you to look over the entire suite of services that our Consumer App offers.
We would, however, be very interested to find out what you can do on our payment platform.

Anything around peer to peer transfer and withdrawal is particularly interesting for us.

Note that you will need an Indonesian phone number to transfer to and from.

Safe Harbor

Any activities in relation to your participation in this program conducted in a manner with full submission and compliance with this Policy Page will be considered authorized conduct and we will not initiate or suggest legal action against you.

If legal action is initiated by a third party against you in connection with your participation in this program, provided that you have fully submitted and complied with this program’s Policy Page, we will make it known that your actions were conducted pursuant to this program and have complied with the Policy Page.

Thank you for helping keep Gojek and our users safe!

FAQ

Q: I want swag, how do I get it?
A: Unfortunately, Gojek does not currently offer any swag.
Q: Can Gojek provide me with a pre-configured test account?
A: As of now, Gojek doesn’t provide any test accounts.
Q: Can we test Gojek Apps outside of the operating country?
A: Yes, we would love to have you participate.


Reward

Asset value CVSS
Low
CVSS
Medium
CVSS
High
CVSS
Critical
Critical
$50$600$1,800$3,500
High
$50$300$600$1,400
Medium
$50$200$350$700

Systemic issues

1st report100%
2nd report100%
3rd report50%
4th report30%
5th report15%
6th+ report5%

We appreciate all valid reports submitted to our program that enhance our security. However, please note that if a similar issue (see definition in 'More info') has already been reported, by you or any other hunter, the reward will be decreasing according to these percentages.


Scopes

ScopeTypeAsset value
*.gojekapi.com
Wildcard
Critical
Low
$50
Medium
$600
High
$1,800
Critical
$3,500
api.gojek.co.id
API
Critical
Low
$50
Medium
$600
High
$1,800
Critical
$3,500
https://play.google.com/store/apps/details?id=com.gojek.app
Mobile application Android
Critical
Low
$50
Medium
$600
High
$1,800
Critical
$3,500
https://apps.apple.com/id/app/gojek/id944875099
Mobile application IOS
Critical
Low
$50
Medium
$600
High
$1,800
Critical
$3,500
gofood.co.id
Web application
High
Low
$50
Medium
$300
High
$600
Critical
$1,400
api.gobiz.co.id
API
High
Low
$50
Medium
$300
High
$600
Critical
$1,400
*.gofood.co.id
Wildcard
Medium
Low
$50
Medium
$200
High
$350
Critical
$700
*.gobiz.co.id
Wildcard
Medium
Low
$50
Medium
$200
High
$350
Critical
$700
portal.gofoodmerchant.co.id
Web application
High
Low
$50
Medium
$300
High
$600
Critical
$1,400
*.gojek.com
Wildcard
Medium
Low
$50
Medium
$200
High
$350
Critical
$700
*.golabs.io
Wildcard
Medium
Low
$50
Medium
$200
High
$350
Critical
$700
*.gofoodmerchant.co.id
Wildcard
Medium
Low
$50
Medium
$200
High
$350
Critical
$700
gocorp.gojek.com
Web application
High
Low
$50
Medium
$300
High
$600
Critical
$1,400
https://play.google.com/store/apps/details?id=com.gojek.resto
Mobile application Android
Critical
Low
$50
Medium
$600
High
$1,800
Critical
$3,500
https://apps.apple.com/sg/app/gojek-driver/id1573529788
Mobile application Android
Critical
Low
$50
Medium
$600
High
$1,800
Critical
$3,500
https://play.google.com/store/apps/details?id=com.gojek.partner
Mobile application Android
Critical
Low
$50
Medium
$600
High
$1,800
Critical
$3,500

Out of scopes

  • Any staging environment will be out of scope (staging domain could be indicated by words like test/integration/staging, etc)
  • All other Goto assets not listed above are to be considered as out of scope

Vulnerability types

Qualifying vulnerabilities

  • SQL Injection (SQLi)
  • Cross-Site Scripting (XSS)
  • Remote Code Execution (RCE)
  • Insecure Direct Object Reference (IDOR)
  • Horizontal and vertical privilege escalation
  • Authentication bypass & broken authentication
  • Business Logic Errors vulnerability with real security impact
  • Local files access and manipulation (LFI, RFI, XXE, SSRF, XSPA)
  • Cross-Origin Resource Sharing (CORS) with real security impact
  • Cross-site Request Forgery (CSRF) with real security impact
  • Open Redirect with real security impact
  • Sensitive Information Exposure Through insecure data storage on device
  • Leaked information from Mobile (without rooting)
  • Insecure Communication
  • Insecure Authentication
  • Insecure Authorization
  • Insufficient Cryptography
  • Hardcoded secrets
  • Exposed secrets, credentials or sensitive information on an asset under our control and affecting at least one of our scopes

Non-qualifying vulnerabilities

  • Subdomain takeover
  • Broken Link/Social media Hijacking
  • Tabnabbing
  • Missing cookie flags
  • Content/Text injections
  • Clickjacking/UI redressing
  • Denial of Service (DoS) attacks
  • Recently disclosed CVEs (less than 30 days sinces patch release)
  • CVEs without exploitable vulnerabilities and PoC
  • Open ports or services without exploitable vulnerabilities and PoC
  • Social engineering of staff or contractors
  • Presence of autocomplete attribute on web forms
  • Vulnerabilities affecting outdated browsers or platforms
  • Self-XSS or XSS that cannot be used to impact other users
  • Any hypothetical flaw or best practices without exploitable vulnerabilities and PoC
  • SSL/TLS issues (e.g. expired certificates, best practices)
  • Open Redirect without real security impact
  • Unexploitable vulnerabilities (e.g. Self-XSS, XSS or Open Redirect through HTTP headers...)
  • Reports with attack scenarios requiring MITM or physical access to victim's device
  • Missing security-related HTTP headers which do not lead directly to an exploitable vulnerability and PoC
  • Low severity Cross-Site Request Forgery (CSRF) (e.g. Unauthenticated / Logout / Login / Products cart updates...)
  • Invalid or missing email security records (e.g. SPF, DKIM, DMARC)
  • Session management issues (e.g. lack of expiration, no logout on password change, concurrent sessions)
  • Disclosure of information without exploitable vulnerabilities and PoC (e.g. stack traces, path disclosure, directory listings, software versions, IP disclosure, 3rd party secrets, EXIF Metadata, Origin IP)
  • CSV injection
  • Malicious file upload (e.g. EICAR files, .EXE)
  • HTTP Strict Transport Security Header (HSTS)
  • Blind SSRF without exploitable vulnerabilities and PoC (e.g. DNS & HTTP pingback, Wordpress XMLRPC)
  • Lack or bypass of rate-limiting, brute-forcing or captcha issues
  • User enumeration (e.g. email, alias, GUID, phone number, common CMS endpoints)
  • Weak password policies (e.g. length, complexity, reuse)
  • Ability to spam users (email / SMS / direct messages flooding)
  • Disclosed or misconfigured public API keys (e.g. Google Maps, Firebase, analytics tools...)
  • Password reset token sent via HTTP referer to external services (e.g. analytics / ads platforms)
  • Stolen secrets, credentials or information gathered from a third-party asset that we have no control over
  • Exposed secrets, credentials or information on an asset under our control that are not applicable to the program’s scope
  • Pre-account takeover (e.g. account creation via oAuth)
  • GraphQL Introspection is enabled
  • Vulnerabilities requiring physical access to a user’s smartphone
  • Exploits that are only possible on Android version 8 and below
  • Exploits that are only possible on IOS version 14 and below
  • Exploits that are only possible on a jailbroken device
  • Exploiting a generic Android or iOS vulnerability.
  • Lack of code obfuscation
  • Lack of binary protection / jailbreak and root detection / anti-debugging controls
  • Crashing your own application
  • Non important secrets (such as 3rd party secrets)
  • SSL cypher suites
  • Vulnerable version of libraries (for example ‘jquery’) without demonstrable attack vector SSL Pinning

Reports of leaks and exposed credentials

In the context of this program, we do not intend to encourage, accept or reward reports of leaks that are not applicable to our program’s scope and policy. To summarize our policy, you may refer to the below table:

Type of leak
Source of leak is in-scope
Source of leak belongs to the Organization and is out-of-scope
Source of leak does not belong to the Organization and is out-of-scope
Impact is in-scope (e.g. valid credentials on an in-scope asset)
checked Eligible
checked Not eligible
checked Not eligible
Impact is out-of-scope (e.g. valid credentials for an out-of-scope asset)
checked Eligible
checked Not eligible
checked Not eligible

Hunting requirements

Account access

No test accounts will be provided.

You can download our consumer app from the Google Play Store or Apple App Store.

The Gojek Consumer app allows for self-registration. You may sign up for an account with your own phone number.

We operate in Indonesia, Singapore, Vietnam and Thailand.

Note: You may get suspended or blocklisted from our platform if we see your profile as one that is making too many fake bookings or one that is not making a single completed booking or for any rate limiting issues as part of our controls.

User agent

Please append to your user-agent header the following value: ' X-YesWeHack-Research: [Your YWH Username] '.


Hunters collaboration

When submitting new report, you can add up to 5 collaborators, and define the reward split ratio.

For more information, see help center.
Note: For reports that have already been rewarded, it is not possible to redistribute the rewards.

To submit a vulnerability report, you need to login with your hunter account.