Bug Bounty

HackerOne Bug Bounty Disclosure: b-improper-session-management-failure-to-invalidate-old-session-after-password-change-b-technolord

Company Name: b'Teleport' Company HackerOne URL: https://hackerone.com/teleport Submitted By:b'technolord1292'Link to Submitters Profile:https://hackerone.com/b'technolord1292' Report Title:b'Improper session management - Failure to invalidate...

HackerOne Bug Bounty Disclosure: b-buffer-overflow-vulnerability-in-websocket-handling-b-dinesh-b

Company Name: b'curl' Company HackerOne URL: https://hackerone.com/curl Submitted By:b'dinesh_b'Link to Submitters Profile:https://hackerone.com/b'dinesh_b' Report Title:b'Buffer Overflow Vulnerability in WebSocket Handling'Report Link:https://hackerone.com/reports/2298307Date...

HackerOne Bug Bounty Disclosure: b-authentication-bypass-on-jetpack-sso-manager-allows-to-access-the-administration-panel-of-wordpress-without-user-interaction-b-sodium

Company Name: b'Automattic' Company HackerOne URL: https://hackerone.com/automattic Submitted By:b'sodium_'Link to Submitters Profile:https://hackerone.com/b'sodium_' Report Title:b'Authentication bypass on JetPack SSO manager -...

HackerOne Bug Bounty Disclosure: b-elasticsearch-is-currently-open-without-authentication-on-https-l-b-roland-hack

Company Name: b'U.S. Dept Of Defense' Company HackerOne URL: https://hackerone.com/deptofdefense Submitted By:b'roland_hack'Link to Submitters Profile:https://hackerone.com/b'roland_hack' Report Title:b'Elasticsearch is currently open...

HackerOne Bug Bounty Disclosure: b-admins-can-change-authentication-details-of-user-configured-external-storage-b-st-nzyy

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'st0nzyy'Link to Submitters Profile:https://hackerone.com/b'st0nzyy' Report Title:b'Admins can change authentication details of user...

HackerOne Bug Bounty Disclosure: b-self-xss-when-pasting-html-into-text-app-with-ctrl-shift-v-b-max-nextcloud

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'max_nextcloud'Link to Submitters Profile:https://hackerone.com/b'max_nextcloud' Report Title:b'Self XSS when pasting HTML into Text...

HackerOne Bug Bounty Disclosure: b-rce-via-file-upload-with-a-null-byte-truncated-file-extension-at-https-b-pizzapower

Company Name: b'U.S. Dept Of Defense' Company HackerOne URL: https://hackerone.com/deptofdefense Submitted By:b'pizzapower'Link to Submitters Profile:https://hackerone.com/b'pizzapower' Report Title:b'RCE via File Upload...

HackerOne Bug Bounty Disclosure: b-mozilla-employee-s-token-for-sql-telemetry-mozilla-org-exposed-in-git-commit-b-yakirka

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'yakirka'Link to Submitters Profile:https://hackerone.com/b'yakirka' Report Title:b"Mozilla Employee's Token for sql.telemetry.mozilla.org...