← The brief
01 · The record
03 · The finder
04 · The programme
Published finding · Bugcrowd
Aiven Managed Bug Bounty A finding accepted against Aiven for OpenSearch. Bugcrowd published no award figure for it.
Everything Bugcrowd published about this
- Programme
- Aiven Managed Bug Bounty In our directory, so it has reviews and a grade.
- Platform handle
- aiven-mbb-og
- Asset
- Aiven for OpenSearch The specific asset the finding landed against, as the platform named it.
- Severity
- medium Bugcrowd rates P1–P5; this is that rating in HackerOne's words so the two feeds can sit in one table.
- Award
- Not published This does not mean nothing was paid. Both platforms let a programme accept a finding without publishing the figure, and most do.
- Found by
- rexnets Named because the finder allowed the platform to name them.
- State
- unresolved — accepted, not yet fixed
- Accepted
- 10 April 2026 6 months ago. This is the date the programme accepted the finding.
- First seen here
- 16 August 2026 When our sweep first read this entry. It says nothing about the finding, only about us.
- Platform reference
- 03686de7-bcd4-4cf5-b92d-d7d87404cb47
What else rexnets has published on Bugcrowd
14published findings
7programmes
2critical
$50,000published awards
- Auth0 by Okta critical · *.cic-bug-bounty.auth0app.com · 6 days ago $50,000
- Gearset: Managed Bug Bounty medium · staging.claytonapp.com · 2 months ago —
- Fivetran medium · *.fivetran.com · 3 months ago —
- Atlassian medium · Any associated *.atlassian.com or *.atl-paas.net domain that can be exploited DIRECTLY from the *.atlassian.net instance · 3 months ago —
- Atlassian high · Any associated *.atlassian.com or *.atl-paas.net domain that can be exploited DIRECTLY from the *.atlassian.net instance · 3 months ago —
- Fivetran low · *.fivetran.com · 4 months ago —
- Atlassian medium · Any associated *.atlassian.com or *.atl-paas.net domain that can be exploited DIRECTLY from the *.atlassian.net instance · 6 months ago —
- Atlassian medium · Any associated *.atlassian.com or *.atl-paas.net domain that can be exploited DIRECTLY from the *.atlassian.net instance · 6 months ago —
Counted within Bugcrowd only. The same handle on another platform may or may not be the same person, and this page will not assume it is.
What else Aiven Managed Bug Bounty has published
- Aiven for Clickhouse low · unresolved · marius_dp · 2 days ago $825
- Aiven for PostgreSQL critical · unresolved · withheld · 6 days ago $15,000
- Aiven for Apache Kafka medium · unresolved · withheld · 11 days ago —
- Aiven for PostgreSQL high · unresolved · withheld · 11 days ago —
- Aiven for PostgreSQL low · unresolved · YX-hueimie · 11 days ago $650
- Aiven for OpenSearch critical · unresolved · dyl0 · 18 days ago $15,000
- Aiven for Clickhouse high · unresolved · dyl0 · 18 days ago $13,200
- Third-party dependency versions critical · unresolved · withheld · 23 days ago —
See Aiven Managed Bug Bounty's grade and researcher reviews →
Where this came from. One row of a public platform feed, stored as published and never edited. We hold no report title, no write-up and no reproduction steps, because the feeds do not carry them and we do not go looking for them. A withheld name stays withheld; if a finder later asks the platform to un-name them, the next sweep un-names them here. Absence of an award figure is publication policy, not evidence a programme did not pay.