Bug Bounty

HackerOne Bug Bounty Disclosure: github-app-link-takeover-listed-on-hxxps-docs-doppler-com-docs-github-actions-page-w-shi

Company Name: Doppler Company HackerOne URL: https://hackerone.com/doppler Submitted By:w3shiLink to Submitters Profile:https://hackerone.com/w3shi Report Title:Github app(link) Takeover Listed on "hXXps://docsdopplercom/docs/github-actions" pageReport...

HackerOne Bug Bounty Disclosure: unauthorized-access-to-offline-publication-cover-pages-via-source-document-id-giwadaoud

Company Name: Publitas Company HackerOne URL: https://hackerone.com/publitas Submitted By:giwadaoudLink to Submitters Profile:https://hackerone.com/giwadaoud Report Title:Unauthorized Access to Offline Publication Cover Pages...

HackerOne Bug Bounty Disclosure: insecure-s-bucket-exposing-git-directory-in-mozilla-foundation-infographics-project-psycho

Company Name: Mozilla Critical Services Company HackerOne URL: https://hackerone.com/mozilla_critical_services Submitted By:psycho_012Link to Submitters Profile:https://hackerone.com/psycho_012 Report Title:Insecure S3 Bucket Exposing Git...

HackerOne Bug Bounty Disclosure: session-doesn-t-expire-after-fa-and-also-other-session-can-change-passsword–xchoudhary

Company Name: SideFX Company HackerOne URL: https://hackerone.com/sidefx Submitted By:0xchoudharyLink to Submitters Profile:https://hackerone.com/0xchoudhary Report Title:Session Doesn't expire after 2fa and also...

HackerOne Bug Bounty Disclosure: -drivers-can-access-the-customers-phone-number-current-location-without-getting-their-offer-accepted-bugsv

Company Name: inDrive Company HackerOne URL: https://hackerone.com/indrive Submitted By:bugsv2Link to Submitters Profile:https://hackerone.com/bugsv2 Report Title:# Drivers can access the customers phone...

HackerOne Bug Bounty Disclosure: disclosure-of-users-ip-address-whenever-they-view-my-fright-offer-on-image-preview-without-interaction-bugsv

Company Name: inDrive Company HackerOne URL: https://hackerone.com/indrive Submitted By:bugsv2Link to Submitters Profile:https://hackerone.com/bugsv2 Report Title:Disclosure of users' ip address whenever they...

HackerOne Bug Bounty Disclosure: oauth-authorization-code-is-valid-indefinetly-mikaelgundersen

Company Name: Nextcloud Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:mikaelgundersenLink to Submitters Profile:https://hackerone.com/mikaelgundersen Report Title:OAuth2 "authorization_code" is valid indefinetlyReport Link:https://hackerone.com/reports/1784162Date Submitted:17...

HackerOne Bug Bounty Disclosure: secure-client-initiated-renegotiation-shewhoisdeath

Company Name: LocalTapiola Company HackerOne URL: https://hackerone.com/localtapiola Submitted By:shewhoisdeathLink to Submitters Profile:https://hackerone.com/shewhoisdeath Report Title:Secure Client-Initiated RenegotiationReport Link:https://hackerone.com/reports/300817Date Submitted:16 February 2024...

HackerOne Bug Bounty Disclosure: multiple-permission-model-bypasses-due-to-improper-path-traversal-sequence-sanitization-xion

Company Name: Node.js Company HackerOne URL: https://hackerone.com/nodejs Submitted By:xionLink to Submitters Profile:https://hackerone.com/xion Report Title:Multiple permission model bypasses due to improper...

HackerOne Bug Bounty Disclosure: non-revoked-api-key-disclosure-in-a-disclosed-api-key-disclosure-report-on-stripo-sankalpa

Company Name: Stripo Inc Company HackerOne URL: https://hackerone.com/stripo Submitted By:sankalpa_1337Link to Submitters Profile:https://hackerone.com/sankalpa_1337 Report Title:Non-revoked API Key Disclosure in a...

HackerOne Bug Bounty Disclosure: hxxp-reading-unprocessed-http-request-with-unbounded-chunk-extension-allows-dos-attacks-bart

Company Name: Node.js Company HackerOne URL: https://hackerone.com/nodejs Submitted By:bartLink to Submitters Profile:https://hackerone.com/bart Report Title:hXXp: Reading unprocessed HTTP request with unbounded...

HackerOne Bug Bounty Disclosure: node-js-is-vulnerable-to-the-marvin-attack-timing-variant-of-the-bleichenbacher-attack-against-pkcs-v-padding-hkario

Company Name: Node.js Company HackerOne URL: https://hackerone.com/nodejs Submitted By:hkarioLink to Submitters Profile:https://hackerone.com/hkario Report Title:Nodejs is vulnerable to the Marvin Attack...

HackerOne Bug Bounty Disclosure: path-traversal-by-monkey-patching-buffer-internals-tniessen

Company Name: Node.js Company HackerOne URL: https://hackerone.com/nodejs Submitted By:tniessenLink to Submitters Profile:https://hackerone.com/tniessen Report Title:Path traversal by monkey-patching Buffer internalsReport Link:https://hackerone.com/reports/2218653Date...