STARBUCKS BUG BOUNTY PROGRAM Starbucksbelievestreats the security of our customers’ personal information with the utmost importance. We believe in a Bug Bounty program that fosters collaboration amongst security professionals to help protect our customers’ personal information from malicious activity due to vulnerabilities against our networks, web and mobile applications and set security policies across our organization.We treat the security and safety of our customers’ personal information with the utmost importance.For the protection of our customers, Starbucks does not disclose, discuss or confirm security matters until comprehensively investigating, diagnosing and fixing any known issues. IfIf you believe you have discovered anissue, please contact us at bugbounty@starbucks.com. PROGRAM RULES Do not intentionally harm the experienceissue orusefulness of the service to others, including degradation of services & denial of service attacks. Do not attempt to view, modify, or damage data belonging to others. Do not disclose the reported vulnerability to others until we’ve had reasonable time to address it. BOUNTY ELIGIBILITY You must agree and adhere to the Program Rules and Legal terms as statedif you are interested inthis policy. You must be the first to report the issue in order to be eligible for bounty. You must be available to supply additional information, as needed bymore information about ourteam, to reproduce and triage the issue. Starbucks Partners are not eligible for participation in this program. TARGETS ELIGIBLE FOR REWARD www.starbucks.com www.starbucks.ca www.starbucks.br www.starbucks.fr www.starbucks.co.uk www.starbucks.de store.starbucks.com www.teavana.com [Starbucks iOS & Android apps for US, CA, BR, FR, UK, DE] (http://www.starbucks.com/coffeehouse/mobile-apps) Starbucks reserves the right to add and subtract fromBug Bounty program, including thelisttypes ofTargets Eligible for Reward and Exclusions. EXCLUSIONS The following vulnerabilities are not eligible for bounty. Denial of Service attacks Descriptive error messages or headers (e.g. Stack Traces, banner grabbing) Disclosure of known public files or directories Outdated software / library versions OPTIONS / TRACE HTTP method enabled CSRF on logout CSRF on formssubmissions that areavailable to anonymous users Cookies that lack HTTP Only or Secure settings for non-sensitive data Self-XSS and issues exploitable only through Self-XSS Reports resulting from automated scanning utilities without additional details or a POC demonstrating a specific exploit Attacks requiring physical access to a user's device Attacks dependent upon social engineering of Starbucks employees or vendors. Username enumeration based on login or forgot password pages. Enforcement policies for brute force, rate limiting, or account lockout SSL/TLS best practices Clickjacking, without additional details demonstrating a specific exploit Mail configuration issues including SPF, DKIM, DMARC settings Use of a known-vulnerable library without a description of an exploit specific to our implementation Password and account recovery policies Presence of autocomplete functionalityinform fields Publicly accessible login panels Lack of email address verification during account registration REWARDS All bounty amounts will be determined at the discretion of the Starbucks Bug Bounty team who will evaluate each report for severity, impact,scope andquality. There could be submissions that we determine have an acceptable levelotherwise out ofrisk such that we do not make changes. WHAT TO INCLUDE IN YOUR REPORT A well written report will allow us to more quickly and accurately triage your submission. A clear description of the issue, including the impact you believe it has to the user, Starbucks, others. Specific reproduction steps including the environment usedscope fortesting (browsers, devices, tools, configuration) and any accounts used during testing. Your recommendations to resolve the issue. LEGAL Starbucks reserves the right to modify terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this site regularlyreward, as well aswe routinely update our program terms and eligibility, which are effective upon posting. We reservetheright to cancel this program at any time. Mustassociated bounty amounts a researcher may be18 or oldereligible tobe eligible for an award.receive, please visit https://hackerone.com/Starbucks
If you'd like to be notified when Starbucks.com makes updates to documents like this, choose which ones you'd like to subscribe to today (it's free!).