Score0.0
Bounty$ 0
SeverityNone

Calculator

Bug Bounty Severity Calculator

This calculator is used to calculate bounties for vulnerabilities reported to our Bug Bounty Program on HackerOne. While our calculator is inspired by the Common Vulnerability Scoring System (CVSS 3.0), there is not a direct mapping between our calculator and CVSS 3.0. Our scoring system takes into consideration Shopify specific context and our current threat model.
Attack Vector

Select what type of vector

Attack Complexity
Vector's value:Low

Measurable effort to exploit

Merchants: Extensive knowledge of target merchant, specific shop configuration, etc.; Shopify: Multiple post-exploitation steps, significant recon, overcoming mitigations/detections, etc.

Privileges Required
Vector's value:None

Requires privileged account

Merchants: requires an account on target shop or partners organization; Shopify: requires access to account to claim subdomain/rubygem, etc.

Does the attacker need extensive permissions?

Merchants: Self-registered accounts are not considered privileged in this context. Requires powerful permission, such as the "Settings" permission; Shopify: Requires access to restricted or beta features, sandboxed environment, etc.

User Interaction
Vector's value:None

Victim performs an action during exploit?

Eg. Click link or button, perform Shopify ID account merge, etc.

Scope Change
Vector's value:Unchanged

Can the attacker impact a separate service?

Merchants: Using Partners to access arbitrary stores; Shopify: Lateral movement to other network services

Confidentiality
Vector's value:None

Data impact?

If the data impacted is sensitive in nature or includes PII, choose High

Does this impact scale to the rest of the service?

For example, in the case of Shopify, could this vector be reasonably scaled to impact any arbitrary Store or does the vector limit the impact to a subset of Stores?

Integrity
Vector's value:None

Data impact?

If the data impacted is sensitive in nature or includes PII, choose High

Does this impact scale to the rest of the service?

For example, in the case of Shopify, could this vector be reasonably scaled to impact any arbitrary Store or does the vector limit the impact to a subset of Stores?

Availability
Vector's value:None

Level of disruption to network service?

How much of the service is impacted?

Merchants: How many merchants? Shopify: How many services? If any are core, choose Most or All

Environment

Score

0.0

Bounty

$ 0

*Not scalable to most or all of Shopify

Severity

None

Vector String