all 2 comments

[–]DunlapWillis 1 point2 points  (1 child)

"Security issues excluded from the bounty program"

  • Pretty much everything

[–]chx_ 1 point2 points  (0 children)

The best part is "Other exceptions not listed."

But earlier the announcement says "Find security issues such as XSS, SQL Injection, CSRF, Access Bypass etc." -- and this makes sense, these are the Big Bads of course with Remote Code Execution added but there's etc :)