Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

Give it a go: Capture the flag for $20K USD in our bug bounty program

Blog post from GitLab

Post Details
Company
Date Published
Author
Heather Simpson
Word Count
598
Company Posts That Month
25
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab has launched a Capture the Flag (CTF) challenge aimed at identifying permission-related vulnerabilities with high business impact but lower CVSS scores, offering a $20,000 USD bounty to the first person who successfully captures a flag by bypassing access control without user interaction. The challenge involves finding a flag within a private project on GitLab.com, and participants must submit a detailed report of their findings through HackerOne to claim the reward. The initiative is designed to enhance security by exposing real-world vulnerabilities and is distinct from other CTFs as it lacks a known solution and is ongoing, with the program being updated on HackerOne once the flag is captured. The use of leaked administrator-privileged tokens is excluded from the CTF but may still qualify for the maximum bounty payout under GitLab's regular bug bounty program. Participants are encouraged to stay informed about the challenge status and CTF availability by subscribing to updates on HackerOne.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.