Travelodge appreciates the investigative work into security vulnerabilities which is carried out by well-intentioned, ethical security researchers. We are committed to thoroughly investigating and resolving security issues in our platform and services in collaboration with the security community. This document defines a method by which we can work with the security research community to improve our online security.
This disclosure policy applies only to vulnerabilities in Travelodge products and services under the following conditions:
The following security issues are currently not in scope (please don’t report them):
We do not offer a paid bug bounty programme. We may, after due consideration, offer a token of appreciation to security researchers who take the time and effort to investigate and report security vulnerabilities to us according to this policy. This is entirely at our discretion. The uniqueness and rating of the vulnerability will be taken into consideration.
If you have discovered an issue which you believe is an in-scope security vulnerability (please see section 2 above for more detail on scope), please email disclosure@travelodge.co.uk including:
In accordance with industry convention, we ask that reporters provide a benign (i.e. non-destructive) proof of exploitation wherever possible. This helps to ensure that the report can be triaged quickly and accurately whilst also reducing the likelihood of duplicate reports and/or malicious exploitation for some vulnerability classes (e.g. sub-domain takeovers). Please ensure that you do not send your proof of exploit in the initial email if the vulnerability is still exploitable. Please also ensure that all proof of exploits is in accordance with our guidance (below), if you are in any doubt, please email disclosure@travelodge.co.uk for advice. Please read this document fully prior to reporting any vulnerabilities to ensure that you understand the policy and can act in compliance with it.
In response to your initial email to disclosure@travelodge.co.uk you will receive an acknowledgement reply email from the Travelodge Security Team, this is usually within 24 hours of your report being received.
The acknowledgment email will include a ticket reference number which you can quote in any further communications with our Security Team.
Following the initial contact, our Security Team will work to triage the reported vulnerability and will respond to you as soon as possible to confirm whether further information is required and/or whether the vulnerability qualifies as per the above scope or is a duplicate report. From this point, necessary remediation work will be assigned to the appropriate teams and/or supplier(s). Priority for bug fixes and/or mitigations will be assigned based on the severity of impact and complexity of exploitation. Vulnerability reports may take some time to triage and/or remediate, you’re welcome to enquire on the status of the process but please limit this to no more than once every 14 days, this helps our Security team focus on the reports as much as possible.
Our Security Team will notify you when the reported vulnerability is resolved (or remediation work is scheduled) and will ask you to confirm that the solution covers the vulnerability adequately. We will offer you the opportunity to feed back to us on the process and relationship as well as the vulnerability resolution. This information will be used in strict confidence to help us improve the way in which we handle reports and/or develop services and resolve vulnerabilities.
Security researchers must not:
We request that any and all data retrieved during research is securely deleted as soon as it is no longer required and at most, 1 month after the vulnerability is resolved, whichever occurs soonest.
If you are unsure at any stage whether the actions you are thinking of taking are acceptable, please contact our security team for guidance (please do not include any sensitive information in the initial communications): disclosure@travelodge.co.uk.
This policy is designed to be compatible with common good practice among well-intentioned security researchers. It does not give you permission to act in any manner that is inconsistent with the law or cause Travelodge to be in breach of any of its legal obligations, including but not limited to:
Travelodge will not seek prosecution of any security researcher who reports, in good faith and in accordance with this policy, any security vulnerability on an in-scope Travelodge service.
If you wish to provide feedback or suggestions on this policy, please contact our security team: disclosure@travelodge.co.uk. This policy will evolve over time and your input will be valued to ensure that it is clear, complete and remains relevant.