Is 5k an appropriate amount for such a finding? Sounds incredibly cheap for such a large organization. How much would something like this be worth on the black market?
I think supply chain attacks are not being taken very seriously. Think that people working, for example, in Python or JavaScript use pip or npm daily no matter if they work for a nuclear agency or your uncle's bar.
>So far, we’ve submitted over 20 bug bounty reports, raking in hundreds of thousands of dollars in bounties.
So I think this is part of a chain of bounties? Though that can still be argued to be a bit too low for how powerful this exploit could be :)
So, as you can hopefully see, it is a balancing act between all parties.
I could be wrong about this, but I've been loud about it around people who do a lot of this stuff and none of them have dunked on me in public. :)