HackerOne Bug Bounty Disclosure: sensitive-data-exposure-via-/secure/querycomponent!default-jspa-endpoint-onbynjmulsqb