
OYO takes all the necessary efforts to mitigate all the bugs & vulnerabilities in our systems. We are open to receiving positive feedback from independent security groups and individual researchers to study it across all platforms and help make OYO technologically safer for our customers. If you discover any such shortfall, we would appreciate a responsible approach in responsibly investigating and reporting it to us so that we can address it as soon as possible. We would further urge you to refrain from any frivolous reporting.
This Policy applies to all of OYO’s group companies/affiliates/subsidiaries (“OYO Group”) including but not limited to all of its domains subsisting worldwide.
Reporting Guidelines
Rules/Terms & Conditions
Changes to Program Terms
Termination & Penalties
In Scope Domains/Apps
Out of Scope Vulnerabilities
Public Disclosure Policy
Indemnification
Acknowledgment/ Declaration
Submit Vulnerability Report
Hall of Fame
Response Targets
1. Participating in OYO’s Responsible Disclosure program requires you to follow the below guidelines. Always use your accounts in the process of investigating any bugs/findings. Don’t target, attempt to access, or otherwise disrupt the accounts of other users.
2. A report must have enough information to reproduce the finding (a proof-of-concept video, code or screenshot etc) and it will only be considered eligible if it pertains to an item explicitly listed under our in-scope sections.
3. In case you find a severe vulnerability that allows system access, you must not proceed further.
4. Do not use scanners or automated tools to find vulnerabilities since they’re noisy and create unnecessary disturbance for the internal security team. Doing so will invalidate your submission and you will be completely banned from the Program.
5. You are obliged to share any additional information as and when requested, failing that will result in rejection of the submission.
6. You should agree to participate in the revalidation & testing of the effectiveness of the countermeasure applied to your report.
7. Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.
Multiple vulnerabilities caused by one underlying issue will be treated as one valid report.
In general, please investigate and report bugs in a way that makes a reasonable, good faith effort not to be disruptive or harmful to us or our users. Otherwise, your actions might be interpreted as an attack rather than an effort to be helpful.
OYO reserves the right to change or discontinue the responsible disclosure program including its policies at any time without any prior notice. OYO may amend this program’s Terms & Conditions and/or its policies at any time by posting a revised version on our website and by continuing your participation in the responsible disclosure program after any such changes, you implicitly agree to comply with the updated program terms.
Violation of any of the given guidelines & T&Cs or any other terms that OYO releases, will immediately ban you from the program and will result in appropriate legal actions. It may also invalidate all your previous contributions and make you liable for penalties as necessary.
OYO: Hotel Booking App Android App
OYO: Search & Book Hotel Rooms iOS App
Maestro Android App
CO OYO iOS App
CO OYO Android App
OYO Campus iOS App
OYO OS Android App
OYO Rocket App
Maestro OYO iOS App
Jedi Audit Android App
OYO Cafe Android App
OYO Lite Android App
OYO Workspaces Android App
Weddingz Android App
OYO Workspaces iOS App
Weddingz iOS App
*.oyorooms.com
*.oyohotels.cn
*.oyoos.com
*.oyohotels.top
*.oyocircle.com preprod.oyorooms.ms patron.oyo.com/blog/in *.oyotimessquare.com *.weddingz.in
*.oyolasvegas.com
*.oyolife.in
*.innov8.work *.oyoworkspaces.com *.oyorooms.io
*.workflobyoyo.com *.oyotownhouse.com
1. Cache related issues
2. Issues related to CMS (WordPress, Joomla etc) misconfiguration without a severe impact
3. Emails (SPF, DMARC, DKIM etc)
4. Banner revealing a software version etc
5. Missing HTTP security headers (Click jacking, HSTS, CSP etc)
6. HTTP methods enabled (OPTIONS / TRACE etc)
7. Missing Cookie Flags (HttpOnly, secure etc)
8. SSL/TLS Versions (BREACH, POODLE etc) or SSL Pinning related
9. Broken Links/Orphan domains - if it doesn’t lead to subdomain takeover
10. Error messages, application stack traces or path disclosures that do not leak sensitive information like credentials or secret tokens etc
11. Kiosk mode / Screen pinning bypass
12. Clipboard data access.
13. Lack of obfuscation or binary protection (anti-debugging) controls
14. Lack of Exploit mitigations i.e. PIE, ARC, or Stack Canaries
15. Tabnabbing
Things that are not eligible:
Researcher shall fully indemnify, hold harmless and defend (collectively “indemnify” and “indemnification”) OYO, its subsidiaries and affiliates, its directors, officers, employees, agents, and shareholders, representatives and third party service providers (collectively, “Indemnified Parties”) from and against all claims, demands, actions, suits, damages, liabilities, losses, settlements, judgments, costs and expenses (including but not limited to reasonable attorney’s fees and costs), whether or not involving a third party claim, which arise out of or relate to:
1. Any breach or violation of the terms of this Responsible Disclosure Policy or any obligation or duty of the Researcher referred therein or under applicable law.
2. Any breach of the confidentiality.
3. Any misuse of data, including personal data.
4. Any breach of any waiver granted.
5. Any attempt to contact OYO’s clients, merchants, partners, users or third parties to inform the existence of the vulnerability. It includes any reference or message in social media making reference to the finding.
6. Any attempt to bring direct or indirectly claims, lawsuits, demands, actions judgments against OYO or any other Indemnified Party, in each case whether or not caused by the negligence of OYO or any other Indemnified Party and whether or not the relevant claim has merit.
OYO holds the benefit of this indemnity and all other rights under this as trustee for each Indemnified Party benefiting from it. OYO’s failure to act with respect to a breach by you or a cause of indemnity as stated above does not waive its right to act with respect to same, subsequent or similar breaches. These indemnification obligations under shall survive any termination or expiration of Policy against you or your exit from Platform. .
By participating in OYO’s Responsible Disclosure Program, you acknowledge that you have read and agree to OYO’s Terms of Service as well as your participation in the Program will not violate any law applicable to you, or disrupt or compromise any data that is not your own.
Type of Response
First response
Second response
Time to resolution
SLA in business days
13 days
7 days
depends on severity and complexity
We’ll try to keep you informed about our progress throughout the process.
We would like to formally and sincerely express our gratitude for the contribution of the security researchers who have responsibly disclosed one or more security vulnerabilities and helped to improve the security of our products or services.
List of Security Researchers can be viewed here.
Copyright © 2022. All rights reserved