New Relic's Coordinated Disclosure Program
nmap
or Burp Suite are perfectly acceptable for research, but we do not want reports generated by automated tools (we already run them in-house).newrelic.com
subdomains with arbitrary HTML and JavaScriptlocalhost
/status
or /metrics
URLs without security impactDomain | *.newrelic.com All New Relic assets are in scope for our coordinated disclosure program, except where otherwise noted. Submissions for assets that are not in scope for a paid bounty are eligible for HackerOne reputation. Services hosted by third party providers are out of scope and should not be tested against. | Eligible | |
Domain | infrastructure.newrelic.com New Relic Infrastructure provides deep, real-time visibility into a company’s dynamic cloud and hybrid infrastructure and integrates seamlessly with New Relic’s application performance solutions. The web application at infrastructure.newrelic.com displays information collected on servers running Infrastructure agents. We recommend familiarizing yourself with the product by reading our documentation. | Eligible | |
Domain | *.infrastructure.newrelic.com | Eligible | |
Domain | *.infrastructure-data.newrelic.com | Eligible | |
Domain | synthetics.newrelic.com New Relic Synthetics provides you with a suite of automated, scriptable tools to monitor your websites, critical business transactions, and API endpoints. The web application at synthetics.newrelic.com displays information from monitors (scripts) running on minions (virtual machines) in our data center or privately within your own infrastructure. We recommend familiarizing yourself with the product by reading our documentation. | Eligible | |
Domain | alerts.newrelic.com New Relic Alerts is a flexible and centralized notification system where you can manage alert policies and conditions for metrics collected by New Relic. This includes data from applications monitored by New Relic APM, servers with the Infrastructure agent¹, Synthetics monitors², and more. When an alert condition is met, a notification is sent out to the specified notification channels. You can learn more in our documentation. | Eligible | |
Domain | docs.newrelic.com Our documentation site is hosted externally by Acquia. Issues within this application or regarding our content should be reported here. No security testing should be done against the platform itself. Any security issues found within the platform should be reported to the Acquia security team. | Eligible | |
Domain | support.newrelic.com Our support landing page provides resources for those looking for help with our products. It also integrates with our ticketing system and links to other areas of interest.
Note that our support ticket system at https://newrelic.zendesk.com is strictly out of scope. | Eligible | |
Domain | discuss.newrelic.com Our discussion forum is a customized Discourse installation. Issues unique to our installation are in scope for bounties. Issues with Discourse itself are not in scope and should not be researched on our instance. Instead, you should follow the guidelines in @discourse and either set up your own instance or use their test instance.
This is an active forum. Spam, brute forcing, and social engineering are strictly forbidden. All care should be made to avoid generating new posts or otherwise affecting the experience of other users on the forum.
Note: No XSS payloads should be attempted unless there is reason to believe our instance is uniquely vulnerable due to our modifications. If an issue is discovered, the payload should immediately be deleted and reported to prevent other users from encountering it. | Eligible | |
Domain | blog.newrelic.com Our blog is hosted externally by Pantheon. Issues within this application or regarding our content should be reported here. No security testing should be done against the platform itself. Any security issues found within the platform should be reported directly to Pantheon.
Unregistered domains or social media accounts linked from this domain are not in scope for bounty. Wordpress | Eligible | |
Domain | learn.newrelic.com Our training portal is hosted externally by Skilljar. Issues within this application or regarding our content should be reported here. No security testing should be done against the platform itself. Any security issues found within the platform should be reported to the Skilljar security team. | Eligible | |
Domain | *.blog.newrelic.com | Eligible | |
Domain | insights.newrelic.com New Relic Insights is a software analytics resource to gather and visualize data. Data can be sent to Insights directly or via other New Relic products. The New Relic Query Language (NRQL), similar to SQL, is a query language for making calls against the Insights event database.
We recommend familiarizing yourself with our Insights documentation and with NRQL queries. Note that while NRQL is very similar to SQL, SQL injection should not be possible. | Eligible | |
Domain | insights.eu.newrelic.com | Eligible | |
Domain | infrastructure.eu.newrelic.com | Eligible | |
Domain | synthetics.eu.newrelic.com | Eligible | |
Domain | rpm.newrelic.com/accounts/*/mobile New Relic Mobile allows you to monitor and manage the performance of your iOS and Android applications by providing end-to-end details, errors, and throughput from every angle in real time. Data shown in New Relic Mobile is generated by agents integrated with iOS and Android applications. | Eligible | |
Domain | rpm.eu.newrelic.com/accounts/*/mobile | Eligible | |
Domain | alerts.eu.newrelic.com | Eligible | |
Domain | *.eu.newrelic.com All New Relic assets in the European region are in scope for our coordinated disclosure program, except where otherwise noted. Submissions for assets that are not in scope for a paid bounty are eligible for HackerOne reputation. Services hosted by third party providers are out of scope and should not be tested against. | Eligible | |
Domain | login.newrelic.com | Eligible | |
Domain | rpm.newrelic.com/accounts/*/browser New Relic Browser provides deep visibility and insight into how your users are interacting with your application or website. New Relic Browser measures page load timing, also known as real user monitoring (RUM), but it goes far beyond that to measure:
With this added functionality, New Relic extends real user monitoring to include the entire life cycle of a page or a view. | Eligible | |
Domain | rpm.eu.newrelic.com/accounts/*/browser | Eligible | |
Domain | developer.newrelic.com | Eligible | |
Domain | rpm.newrelic.com New Relic's software analytics product for application performance monitoring (APM) delivers real-time and trending data about your web application's performance and the level of satisfaction that your end users experience. With end to end transaction tracing and a variety of color-coded charts and reports, APM visualizes your data, down to the deepest code levels. | Eligible | |
Domain | one.newrelic.com New Relic One is the industry’s first entity-centric observability platform. This platform allows our customers to view across accounts and products, and will be the home of our future innovations. | Eligible | |
Domain | *.nr-data.net | Eligible | |
Domain | *.nr-ops.net | Eligible | |
Other | Synthetics minions (public and private) Synthetics minions are sandboxed virtual machines that run monitors (scripts) to gather information about your websites, critical business transactions, and API endpoints. Minions can run in our data center or privately within your own infrastructure. We recommend familiarizing yourself with the product by reading our documentation.
Note that out-of-date packages running on these minions are not in scope for this program. Minions are intended to be updated from within the VM or with future releases. | Eligible | |
Other | Agent traffic The New Relic agents are designed to collect data and send it back for display within the New Relic products. Traffic between the agents and New Relic backend services may be inspected and reports concerning issues with how the agent connects and transports information are acceptable. | Eligible | |
Android: Play Store | com.newrelic.rpm The New Relic Android app lets you access your data wherever you are. Receive alerts, view, query, and share dashboards, and more all from your mobile device. | Eligible | |
Executable | Infrastructure agents The New Relic Infrastructure agents are used to send information (running processes, memory usage, etc.) from Windows and Linux servers to be viewed within the New Relic web application. We may provide rewards for security issues found within the Infrastructure agent that could reduce the security of the systems the agent runs on. Rewards are based on the default configuration settings, but agents that show problems due to a configuration change may be eligible for a reward. | Eligible | |
Executable | Go agent The New Relic Go agent is installed within a supported Go application. It is designed to collect data about the running application and send it back for display within New Relic APM. We may provide rewards for security issues found within the Go agent that could reduce the security of the application the agent is integrated with. Rewards are based on the default configuration settings, but agents that show problems due to a configuration change may be eligible for a reward.
Source code for this agent can be inspected on GitHub. | Eligible | |
Executable | Node.js agent The New Relic Node.js agent can by installed via
npm within a supported Node.js application. It is designed to collect data about the running application and send it back for display within New Relic APM. We may provide rewards for security issues found within the Node.js agent that could reduce the security of the application the agent is integrated with. Rewards are based on the default configuration settings, but agents that show problems due to a configuration change may be eligible for a reward.Source code for this agent can be inspected on GitHub. | Eligible | |
Executable | Ruby agent The New Relic Ruby agent is installed as a Ruby gem within a supported Ruby application. It is designed to collect data about the running application and send it back for display within New Relic APM. We may provide rewards for security issues found within the Ruby agent that could reduce the security of the application the agent is integrated with. Rewards are based on the default configuration settings, but agents that show problems due to a configuration change may be eligible for a reward.
Source code for this agent can be inspected on GitHub. | Eligible | |
Executable | Unity agent The New Relic Unity agent is installed within a Unity application on iOS or Android. It is designed to collect data about the running application and send it back for display within New Relic Mobile. We may provide rewards for security issues found within the Unity agent that could reduce the security of the application the agent is integrated with. Rewards are based on the default configuration settings, but agents that show problems due to a configuration change may be eligible for a reward. | Eligible | |
Executable | PHP agent The New Relic PHP agent can be installed within a supported PHP application. It is designed to collect data about the running application and send it back for display within New Relic APM. We may provide rewards for security issues found within the PHP agent that could reduce the security of the application the agent is integrated with. Rewards are based on the default configuration settings, but agents that show problems due to a configuration change may be eligible for a reward. | Eligible | |
Executable | .NET agent The New Relic .NET agent can by installed within a supported .NET Framework application. It is designed to collect data about the running application and send it back for display within New Relic APM. We may provide rewards for security issues found within the .NET Framework agent that could reduce the security of the application the agent is integrated with. Rewards are based on the default configuration settings, but agents that show problems due to a configuration change may be eligible for a reward. | Eligible | |
Executable | .NET Core agent The New Relic .NET Core agent can by installed within a supported .NET Core application. It is designed to collect data about the running application and send it back for display within New Relic APM. We may provide rewards for security issues found within the .NET Core agent that could reduce the security of the application the agent is integrated with. Rewards are based on the default configuration settings, but agents that show problems due to a configuration change may be eligible for a reward. | Eligible | |
Executable | Java agent The New Relic Java agent can by installed within a supported Java application. It is designed to collect data about the running application and send it back for display within New Relic APM. We may provide rewards for security issues found within the Java agent that could reduce the security of the application the agent is integrated with. Rewards are based on the default configuration settings, but agents that show problems due to a configuration change may be eligible for a reward. | Eligible | |
Executable | Python agent The New Relic Python agent can by installed with Pip within a supported Python application. It is designed to collect data about the running application and send it back for display within New Relic APM. We may provide rewards for security issues found within the Python agent that could reduce the security of the application the agent is integrated with. Rewards are based on the default configuration settings, but agents that show problems due to a configuration change may be eligible for a reward. | Eligible | |
Executable | Browser agent The New Relic Browser agent is deployed as a JavaScript snippet by way of a supported APM agent or web application. It is designed to collect data about the running application and send it back for display within New Relic Browser. We may provide rewards for security issues found within the Browser agent that could reduce the security of the browser the agent is running within. Rewards are based on the default configuration settings, but agents that show problems due to a configuration change may be eligible for a reward. | Eligible | |
Executable | Android agent The New Relic Android agent is installed via Gradle within a supported Android application. It is designed to collect data about the running application and send it back for display within New Relic Mobile. We may provide rewards for security issues found within the Android agent that could reduce the security of the application the agent is integrated with. Rewards are based on the default configuration settings, but agents that show problems due to a configuration change may be eligible for a reward. | Eligible | |
Executable | iOS agent The New Relic iOS agent is installed as a framework or via CocoaPods within a supported iOS application. It is designed to collect data about the running application and send it back for display within New Relic Mobile. We may provide rewards for security issues found within the iOS agent that could reduce the security of the application the agent is integrated with. Rewards are based on the default configuration settings, but agents that show problems due to a configuration change may be eligible for a reward. | Eligible | |
iOS: App Store | com.newrelic.NRApp The New Relic iOS app lets you access your data wherever you are. Receive alerts, view, query, and share dashboards, and more all from your mobile device. | Eligible |
Domain | try.newrelic.com This domain is related to a service hosted externally by Marketo and should not be targeted for any security testing. Any security issues found should be reported to the Marketo security team. |
Domain | ir.newrelic.com Our investor relations portal is hosted externally by Q4 Inc. and should not be targeted for any security testing. Any security issues found should be reported directly to Q4 Inc. |
Domain | status.newrelic.com Our status page is hosted externally by Atlassian Statuspage and should not be targeted for any security testing. Any security issues found should be reported to the StatusPage.io coordinated disclosure program. |
Domain | newrelic.zendesk.com |
Domain | t.newrelic.com This domain is related to a service hosted externally by SalesLoft and should not be targeted for any security testing. Any security issues found should be reported to the SalesLoft security team. |
Domain | issues.newrelic.com This domain is related to the New Relic issue tracker and must not be targeted for any security testing; reports against this asset will be marked as N/A. |
Domain | staging.issues.newrelic.com This domain is related to the New Relic issue tracker and must not be targeted for any security testing; reports against this asset will be marked as N/A. |