bug bounty

HackerOne Bug Bounty Disclosure: b-self-xss-when-pasting-html-into-text-app-with-ctrl-shift-v-b-max-nextcloud

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'max_nextcloud'Link to Submitters Profile:https://hackerone.com/b'max_nextcloud' Report Title:b'Self XSS when pasting HTML into Text...

HackerOne Bug Bounty Disclosure: b-rce-via-file-upload-with-a-null-byte-truncated-file-extension-at-https-b-pizzapower

Company Name: b'U.S. Dept Of Defense' Company HackerOne URL: https://hackerone.com/deptofdefense Submitted By:b'pizzapower'Link to Submitters Profile:https://hackerone.com/b'pizzapower' Report Title:b'RCE via File Upload...

HackerOne Bug Bounty Disclosure: b-mozilla-employee-s-token-for-sql-telemetry-mozilla-org-exposed-in-git-commit-b-yakirka

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'yakirka'Link to Submitters Profile:https://hackerone.com/b'yakirka' Report Title:b"Mozilla Employee's Token for sql.telemetry.mozilla.org...

HackerOne Bug Bounty Disclosure: b-uri-parser-s-rfc-regular-expression-has-poor-performance-when-there-are-two-characters-leading-to-redos-b-dee-see

Company Name: b'Ruby' Company HackerOne URL: https://hackerone.com/ruby Submitted By:b'dee-see'Link to Submitters Profile:https://hackerone.com/b'dee-see' Report Title:b"URI parser's RFC3986 regular expression has poor...

HackerOne Bug Bounty Disclosure: b-web-api-key-registration-allows-registering-multiple-keys-by-reusing-request-id-b-xpaw

Company Name: b'Valve' Company HackerOne URL: https://hackerone.com/valve Submitted By:b'xpaw'Link to Submitters Profile:https://hackerone.com/b'xpaw' Report Title:b'Web API key registration allows registering multiple...

HackerOne Bug Bounty Disclosure: b-default-credential-to-login-at-site-management-panel-b-abhhinavsecondary

Company Name: b'Daimler Truck' Company HackerOne URL: https://hackerone.com/daimler_truck Submitted By:b'abhhinavsecondary'Link to Submitters Profile:https://hackerone.com/b'abhhinavsecondary' Report Title:b'Default credential to login at site...

HackerOne Bug Bounty Disclosure: b-misconfiguration-in-aws-cloudfront-cdn-configuration-makes-rubygems-org-serve-and-cache-content-from-a-unclaimed-s-bucket-b-p-fg

Company Name: b'Internet Bug Bounty' Company HackerOne URL: https://hackerone.com/ibb Submitted By:b'p4fg'Link to Submitters Profile:https://hackerone.com/b'p4fg' Report Title:b'Misconfiguration in AWS CloudFront CDN...

HackerOne Bug Bounty Disclosure: b-csrf-that-makes-any-linkedin-user-follow-attacker-controlled-accounts-by-simply-clicking-https-www-linkedin-com-comm-mynetwork-discovery-see-all-b-marvelmaniac

Company Name: b'LinkedIn' Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b'marvelmaniac'Link to Submitters Profile:https://hackerone.com/b'marvelmaniac' Report Title:b'CSRF that makes any linkedin user follow...

HackerOne Bug Bounty Disclosure: b-user-details-can-be-disclosed-even-if-the-account-is-in-hibernation-state-b-tushar

Company Name: b'LinkedIn' Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b'tushar6378'Link to Submitters Profile:https://hackerone.com/b'tushar6378' Report Title:b'User Details Can Be Disclosed Even If...

HackerOne Bug Bounty Disclosure: b-csrf-that-makes-any-user-send-invitations-to-the-attacker-by-simply-clicking-on-a-link-b-marvelmaniac

Company Name: b'LinkedIn' Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b'marvelmaniac'Link to Submitters Profile:https://hackerone.com/b'marvelmaniac' Report Title:b'CSRF that makes any user send invitations...