Dow Jones · Vulnerability Disclosure

Dow Jones Vulnerability Disclosure

Vulnerability disclosure

Dow Jones runs a coordinated vulnerability disclosure program on Bugcrowd. A dedicated security contact is published.

FinancialMarket DataNewsPublishingRisk and ComplianceScreeningDue DiligenceMedia Monitoring
Program: Bugcrowd

Disclosure Policy

Security Contact

Contact
emailVDP@dowjones.com
Contact
intakeReporters email VDP@dowjones.com with the information listed on Bugcrowd's "Report a Bug" page. Dow Jones forwards the report to Bugcrowd.

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
source: https://www.dowjones.com/security/
program:
  name: Dow Jones Vulnerability Disclosure Program
  url: https://www.dowjones.com/security/
  http_status: 200
  effective_date: '2021-06-24'
  managed_by: Bugcrowd
  type: vulnerability-disclosure-program
  bug_bounty: false
  bounty_note: >-
    Published as a disclosure program, not a paid bounty. No reward table, scope list or safe-harbour
    legal language is published on the Dow Jones page itself; submissions are governed by Bugcrowd's
    Standard Disclosure Terms.
contact:
  email: VDP@dowjones.com
  intake: >-
    Reporters email VDP@dowjones.com with the information listed on Bugcrowd's "Report a Bug" page.
    Dow Jones forwards the report to Bugcrowd.
terms:
  - label: Bugcrowd Standard Disclosure Terms
    url: https://www.bugcrowd.com/resource/standard-disclosure-terms/
  - label: Bugcrowd — Reporting a Bug
    url: https://docs.bugcrowd.com/researchers/reporting-managing-submissions/reporting-a-bug/
policy_statements:
  - Dow Jones investigates all reported vulnerabilities in its information assets.
  - >-
    Reporters are asked not to post or share information about a potential vulnerability publicly
    until Dow Jones has researched, responded to and addressed it.
security_txt:
  served: false
  note: >-
    No RFC 9116 security.txt is served. Probed 2026-08-13 — www.dowjones.com/.well-known/security.txt 404,
    www.dowjones.com/security.txt 404, api.dowjones.com/.well-known/security.txt 404,
    developer.dowjones.com/.well-known/security.txt 404, accounts.dowjones.com/.well-known/security.txt 404,
    eu.api.dowjones.com/.well-known/security.txt 404, api-thirdparty.riskcenter.dowjones.com/.well-known/security.txt 404.
    A machine-readable security.txt pointing at https://www.dowjones.com/security/ and VDP@dowjones.com
    is the single cheapest fix available here — the policy exists, it is just not discoverable by a crawler.
x-evidence:
  fetched: '2026-08-13'
  probes:
    - url: https://www.dowjones.com/security/
      status: 200
    - url: https://www.dowjones.com/responsible-disclosure
      status: 404
    - url: https://www.dowjones.com/.well-known/security.txt
      status: 404