Bug Bounty

HackerOne Bug Bounty Disclosure: b-uri-parser-s-rfc-regular-expression-has-poor-performance-when-there-are-two-characters-leading-to-redos-b-dee-see

Company Name: b'Ruby' Company HackerOne URL: https://hackerone.com/ruby Submitted By:b'dee-see'Link to Submitters Profile:https://hackerone.com/b'dee-see' Report Title:b"URI parser's RFC3986 regular expression has poor...

HackerOne Bug Bounty Disclosure: b-web-api-key-registration-allows-registering-multiple-keys-by-reusing-request-id-b-xpaw

Company Name: b'Valve' Company HackerOne URL: https://hackerone.com/valve Submitted By:b'xpaw'Link to Submitters Profile:https://hackerone.com/b'xpaw' Report Title:b'Web API key registration allows registering multiple...

HackerOne Bug Bounty Disclosure: b-default-credential-to-login-at-site-management-panel-b-abhhinavsecondary

Company Name: b'Daimler Truck' Company HackerOne URL: https://hackerone.com/daimler_truck Submitted By:b'abhhinavsecondary'Link to Submitters Profile:https://hackerone.com/b'abhhinavsecondary' Report Title:b'Default credential to login at site...

HackerOne Bug Bounty Disclosure: b-misconfiguration-in-aws-cloudfront-cdn-configuration-makes-rubygems-org-serve-and-cache-content-from-a-unclaimed-s-bucket-b-p-fg

Company Name: b'Internet Bug Bounty' Company HackerOne URL: https://hackerone.com/ibb Submitted By:b'p4fg'Link to Submitters Profile:https://hackerone.com/b'p4fg' Report Title:b'Misconfiguration in AWS CloudFront CDN...

HackerOne Bug Bounty Disclosure: b-csrf-that-makes-any-linkedin-user-follow-attacker-controlled-accounts-by-simply-clicking-https-www-linkedin-com-comm-mynetwork-discovery-see-all-b-marvelmaniac

Company Name: b'LinkedIn' Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b'marvelmaniac'Link to Submitters Profile:https://hackerone.com/b'marvelmaniac' Report Title:b'CSRF that makes any linkedin user follow...

HackerOne Bug Bounty Disclosure: b-user-details-can-be-disclosed-even-if-the-account-is-in-hibernation-state-b-tushar

Company Name: b'LinkedIn' Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b'tushar6378'Link to Submitters Profile:https://hackerone.com/b'tushar6378' Report Title:b'User Details Can Be Disclosed Even If...

HackerOne Bug Bounty Disclosure: b-csrf-that-makes-any-user-send-invitations-to-the-attacker-by-simply-clicking-on-a-link-b-marvelmaniac

Company Name: b'LinkedIn' Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b'marvelmaniac'Link to Submitters Profile:https://hackerone.com/b'marvelmaniac' Report Title:b'CSRF that makes any user send invitations...

HackerOne Bug Bounty Disclosure: b-rogue-collaborators-and-ambiguous-branch-names-in-github-b-inspector-ambitious

Company Name: b'GitHub' Company HackerOne URL: https://hackerone.com/github Submitted By:b'inspector-ambitious'Link to Submitters Profile:https://hackerone.com/b'inspector-ambitious' Report Title:b'Rogue collaborators and ambiguous branch names in...

HackerOne Bug Bounty Disclosure: b-unauthenticated-remote-access-to-testing-endpoint-b-sajidraza

Company Name: b'IBM' Company HackerOne URL: https://hackerone.com/ibm Submitted By:b'sajidraza'Link to Submitters Profile:https://hackerone.com/b'sajidraza' Report Title:b'Unauthenticated Remote Access to Testing Endpoint'Report Link:https://hackerone.com/reports/2192984Date...

HackerOne Bug Bounty Disclosure: b-mozilla-fuzzmanager-api-token-exposed-in-git-commit-b-yakirka

Company Name: b'Mozilla Critical Services' Company HackerOne URL: https://hackerone.com/mozilla_critical_services Submitted By:b'yakirka'Link to Submitters Profile:https://hackerone.com/b'yakirka' Report Title:b'Mozilla FuzzManager API Token Exposed...

HackerOne Bug Bounty Disclosure: b-multiple-path-transversal-vulnerabilites-b-myselfphoton

Company Name: b'Tor' Company HackerOne URL: https://hackerone.com/torproject Submitted By:b'myselfphoton'Link to Submitters Profile:https://hackerone.com/b'myselfphoton' Report Title:b'Multiple Path Transversal Vulnerabilites'Report Link:https://hackerone.com/reports/273377Date Submitted:28 November...

HackerOne Bug Bounty Disclosure: b-https-get-ooni-torproject-org-b-ba-fe-ca-d-f-a

Company Name: b'Tor' Company HackerOne URL: https://hackerone.com/torproject Submitted By:b'ba4fe4ca95021d367f8a574'Link to Submitters Profile:https://hackerone.com/b'ba4fe4ca95021d367f8a574' Report Title:b'https://get.ooni.torproject.org/'Report Link:https://hackerone.com/reports/274285Date Submitted:28 November 2023 A considerable...

HackerOne Bug Bounty Disclosure: b-report-regarding-security-vulnerability-b-srkfan

Company Name: b'Tor' Company HackerOne URL: https://hackerone.com/torproject Submitted By:b'srkfan'Link to Submitters Profile:https://hackerone.com/b'srkfan' Report Title:b'Report Regarding Security Vulnerability'Report Link:https://hackerone.com/reports/269243Date Submitted:28 November...

HackerOne Bug Bounty Disclosure: b-use-of-unitialized-value-in-crypto-pk-num-bits-src-common-crypto-c-b-geeknik

Company Name: b'Tor' Company HackerOne URL: https://hackerone.com/torproject Submitted By:b'geeknik'Link to Submitters Profile:https://hackerone.com/b'geeknik' Report Title:b'Use of unitialized value in crypto_pk_num_bits (src/common/crypto.c:971)'Report...

HackerOne Bug Bounty Disclosure: b-potential-ip-revealing-using-unc-path-in-windows-file-picker-b-newfunction

Company Name: b'Tor' Company HackerOne URL: https://hackerone.com/torproject Submitted By:b'newfunction'Link to Submitters Profile:https://hackerone.com/b'newfunction' Report Title:b'Potential IP revealing using UNC Path in...