Twilio

Twilio

Bounty RecognitionFull Safe Harbor

Program Details

Handle
twilio
Managed
Yes

Response Metrics

Response Time
5 days
Bounty Time
57 days
Resolution Time
4868 days
Response Efficiency
84%

Scope (24 targets)

web: 13 mobile: 2 other: 9

Bounty splitting: Yes

In Scope

  • *.sip.*.twilio.com web bounty-eligible
  • Any host/web property verified to be owned by Twilio et al. other bounty-eligible
  • Twilio APIs other bounty-eligible
  • api.segment.io other bounty-eligible
  • api.sendgrid.com web bounty-eligible
  • api.twilio.com other bounty-eligible
  • app.segment.com web bounty-eligible
  • app.sendgrid.com web bounty-eligible
  • http://help.twilio.com web bounty-eligible
  • http://tsock.us1.twilio.com web bounty-eligible
  • http://twilio.com/blog web bounty-eligible
  • https://segment.com/docs/connections/sources/ web bounty-eligible
  • https://www.authy.com/download/ mobile bounty-eligible
  • https://www.authy.com/download/ mobile bounty-eligible
  • https://www.twilio.com/docs/authy/api other bounty-eligible
  • https://www.twilio.com/docs/libraries other bounty-eligible
  • https://www.twilio.com/docs/verify/api other bounty-eligible
  • https://www.twilio.com/en-us/blog/get-started-webrtc other bounty-eligible
  • https://www.twilio.com/login?g=%2fconsole%3f&t=2b1c98334b25c1a785ef15b6556396290e3c704a9b57fc40687cbccd79c46a8c web bounty-eligible
  • mc.sendgrid.com web bounty-eligible
  • and 4 more targets

Out of Scope

All Kurento domains, All Twilio acquisitions until explicitly noted under the in-scope targets, Electric Imp and its assets, Third-party services, Twilio Quest, Twilio Wireless, TwimlBins, Ytica and its assets, community.segment.com, http://apjevents.twilio.com, http://events.cdpweek.com, http://segment.com/contact, http://segment.com/jobs, http://twilio.com/en-us/company/jobs, http://twilio.com/labs, jobs.twilio.com, lab.authy.com, signal.twilio.com, status.segment.com, status.sendgrid.com, status.twilio.com, store.twilio.com, support.sendgrid.com, support.twilio.com, surveys.twilio.com, talks.twilio.com, transform.twilio.com, twil.io, twiliotraining.com, webinars.segment.com, webinars.twilio.com, zipwhip.com

Known Exploited Vulnerabilities 1CVE

  • CVE-2024-39891AuthyJul 23, 202417.1% EPSS

    Twilio Authy contains an information disclosure vulnerability in its API that allows an unauthenticated endpoint to accept a request containing a phone number and respond with information about whether the phone number was registered with Authy.

Additional Info

Sources
bugcrowd