huntr icon indicating copy to clipboard operation
huntr copied to clipboard

Fix bounty is too low

Open carakas opened this issue 2 years ago • 3 comments

Is your feature request related to a problem? Please describe. I'm always frustrated when I get a low-quality report that takes a lot of time to fix but a huge part of the bounty still goes to the reporter.

Describe the solution you'd like A better way of balancing the bounties, either automatically or manually based on the quality of the report and time needed for the fix.

Describe alternatives you've considered Split the bounties half-half again like it used to be

carakas avatar Nov 14 '21 22:11 carakas

I noticed a CSRF was $3.75 to fix for a single occurrence. However another CSRF disclosure on same repo with 15ish occurrences is still only $3.75 to fix.....seems odd....i would think it would be more incentive to the maintainer if the fix bounty also raised per occurrence like the disclosures do. Just my two cents.

HDVinnie avatar Dec 02 '21 15:12 HDVinnie

As a researcher, when I bundle up my occurences, I see that the maintainer will get less money (because the prize pot will decrease) even though they have more to fix. So I agree that the fix bounty should match up to original vulnerability+occurence

Haxatron avatar Dec 03 '21 06:12 Haxatron

I think it is fair to calculate the fix bonus based on the number occurrences + current fix bonuses..

jaapmarcus avatar Dec 06 '21 10:12 jaapmarcus