bug bounty

HackerOne Bug Bounty Disclosure: replayable-password-change-request-across-sessions-mantu

Company Name: Malwarebytes Company HackerOne URL: https://hackerone.com/malwarebytes Submitted By:mantu1738Link to Submitters Profile:https://hackerone.com/mantu1738 Report Title:Replayable Password Change Request Across SessionsReport Link:https://hackerone.com/reports/3269777Date...

HackerOne Bug Bounty Disclosure: -x-vc-index-js-exposed-google-maps-api-key-allowing-potential-abuse-of-paid-services-abdallasamir

Company Name: 8x8 Bounty Company HackerOne URL: https://hackerone.com/8x8-bounty Submitted By:abdallasamir12Link to Submitters Profile:https://hackerone.com/abdallasamir12 Report Title:8x8vc/indexjs: Exposed Google Maps API Key...

HackerOne Bug Bounty Disclosure: url-path-manipulation-enables-cache-poisoning-of-amazon-affiliate-products-in-shopify-linkpop-saltymermaid

Company Name: Shopify Company HackerOne URL: https://hackerone.com/shopify Submitted By:saltymermaidLink to Submitters Profile:https://hackerone.com/saltymermaid Report Title:URL Path Manipulation Enables Cache Poisoning of...

HackerOne Bug Bounty Disclosure: remote-code-execution-in-amazon-mwaa-due-to-outdated-apache-airflow-version-ricardojoserf

Company Name: AWS VDP Company HackerOne URL: https://hackerone.com/aws_vdp Submitted By:ricardojoserfLink to Submitters Profile:https://hackerone.com/ricardojoserf Report Title:Remote Code Execution in Amazon MWAA...

BugCrowd Bug Bounty Disclosure: P5 – Unauthenticated metadata disclosure of protected NASA flight reports and mission schedules via /ajax/activity – madhu873

Unauthenticated metadata disclosure of protected NASA flight reports and mission schedules via /ajax/activity Unauthenticated metadata disclosure of protected NASA flight...

HackerOne Bug Bounty Disclosure: exposure-of-hard-coded-private-keys-and-credentials-in-curl-source-repository-cwe-spectre

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:spectre-1Link to Submitters Profile:https://hackerone.com/spectre-1 Report Title:Exposure of Hard-coded Private Keys and Credentials...

HackerOne Bug Bounty Disclosure: unsafe-global-ifs-modification-in-os-shell-script-enables-command-injection-and-parsing-flaws-cwe-cwe-spectre

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:spectre-1Link to Submitters Profile:https://hackerone.com/spectre-1 Report Title:Unsafe Global IFS Modification in OS400 Shell...

HackerOne Bug Bounty Disclosure: insecure-websocket-usage-in-curl-documentation-and-examples-cwe-cleartext-transmission-of-sensitive-information-spectre

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:spectre-1Link to Submitters Profile:https://hackerone.com/spectre-1 Report Title:Insecure WebSocket Usage in curl Documentation and...

HackerOne Bug Bounty Disclosure: account-repository-takeover-via-abandoned-github-username-in-curl-s-href-extractor-c-ks-karem

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:ks_karem77Link to Submitters Profile:https://hackerone.com/ks_karem77 Report Title:Account/Repository Takeover via Abandoned GitHub Username in...

HackerOne Bug Bounty Disclosure: heap-buffer-overflow-in-curl-memdup-via-curlopt-copypostfields-curlopt-postfieldsize-mismatch-geeknik

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:geeknikLink to Submitters Profile:https://hackerone.com/geeknik Report Title:Heap Buffer Overflow in Curl_memdup0() via CURLOPT_COPYPOSTFIELDS/CURLOPT_POSTFIELDSIZE...

BugCrowd Bug Bounty Disclosure: P3 – Critical Identity and Communication Data Exposed in Unprotected NASA Hangar Demolition Doc Vulnerability – Black_charon

Critical Identity and Communication Data Exposed in Unprotected NASA Hangar Demolition Doc Vulnerability Critical Identity and Communication Data Exposed in...

HackerOne Bug Bounty Disclosure: man-in-the-middle-through-broken-ssl-certificate-verification-kinnay

Company Name: Nintendo Company HackerOne URL: https://hackerone.com/nintendo Submitted By:kinnayLink to Submitters Profile:https://hackerone.com/kinnay Report Title:Man-in-the-middle through broken SSL certificate verificationReport Link:https://hackerone.com/reports/3174987Date...

HackerOne Bug Bounty Disclosure: unauthorized-disclosure-of-private-emails-via-wakatime-private-leaderboards-ctrl-cipher

Company Name: WakaTime Company HackerOne URL: https://hackerone.com/wakatime Submitted By:ctrl_cipherLink to Submitters Profile:https://hackerone.com/ctrl_cipher Report Title:Unauthorized Disclosure of Private Emails via WakaTime...

HackerOne Bug Bounty Disclosure: integer-overflow-in-schannel-c-tls-data-transmission-kakorrhaphiophobia

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:kakorrhaphiophobiaLink to Submitters Profile:https://hackerone.com/kakorrhaphiophobia Report Title:Integer Overflow in schannelc TLS Data TransmissionReport...

HackerOne Bug Bounty Disclosure: stack-use-after-scope-in-http-post-request-processing-via-curlopt-postfields-geeknik

Company Name: curl Company HackerOne URL: https://hackerone.com/curl Submitted By:geeknikLink to Submitters Profile:https://hackerone.com/geeknik Report Title:Stack use-after-scope in HTTP/3 POST request processing...