bug bounty

HackerOne Bug Bounty Disclosure: b-unauthorized-access-to-deleted-interviews-on-glassdoor-platform-b-frankcadillac

Company Name: b'Glassdoor' Company HackerOne URL: https://hackerone.com/glassdoor Submitted By:b'frankcadillac'Link to Submitters Profile:https://hackerone.com/b'frankcadillac' Report Title:b'Unauthorized Access to Deleted Interviews on Glassdoor...

HackerOne Bug Bounty Disclosure: b-cve-apache-airflow-dag-runs-broken-access-control-vulnerability-b-happyhacking

Company Name: b'Internet Bug Bounty' Company HackerOne URL: https://hackerone.com/ibb Submitted By:b'happyhacking123'Link to Submitters Profile:https://hackerone.com/b'happyhacking123' Report Title:b'CVE-2023-40611: Apache Airflow Dag Runs...

HackerOne Bug Bounty Disclosure: b-rce-on-ingress-nginx-controller-via-ingress-spec-rules-http-paths-path-field-b-ginoah

Company Name: b'Kubernetes' Company HackerOne URL: https://hackerone.com/kubernetes Submitted By:b'ginoah'Link to Submitters Profile:https://hackerone.com/b'ginoah' Report Title:b'RCE on ingress-nginx-controller via Ingress spec.rules.http.paths.path field'Report...

HackerOne Bug Bounty Disclosure: b-new-search-feature-search-for-non-public-words-in-limited-disclosure-reports-b-ahacker

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'ahacker1'Link to Submitters Profile:https://hackerone.com/b'ahacker1' Report Title:b'New Search Feature: Search for non-public words...

HackerOne Bug Bounty Disclosure: b-blind-ssrf-on-https-my-exnessaffiliates-com-allows-for-internal-network-enumeration-b-null-hypothesis

Company Name: b'EXNESS' Company HackerOne URL: https://hackerone.com/exness Submitted By:b'null_hypothesis'Link to Submitters Profile:https://hackerone.com/b'null_hypothesis' Report Title:b'Blind SSRF on https://my.exnessaffiliates.com/ allows for internal...

HackerOne Bug Bounty Disclosure: b-accessing-apps-protected-via-zt-s-access-when-user-account-is-deleted-disabled-even-after-clearing-user-session-seat-b-suzuka

Company Name: b'Cloudflare Public Bug Bounty' Company HackerOne URL: https://hackerone.com/cloudflare Submitted By:b'suzuka'Link to Submitters Profile:https://hackerone.com/b'suzuka' Report Title:b"Accessing apps protected via...

HackerOne Bug Bounty Disclosure: b-deny-admin-from-editing-linkedin-company-page-using-gen-form-visibility-via-post-voyager-api-voyagerorganizationdashcompanies-id-b-domg

Company Name: b'LinkedIn' Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b'domg'Link to Submitters Profile:https://hackerone.com/b'domg' Report Title:b'Deny Admin from Editing LinkedIn Company Page...

HackerOne Bug Bounty Disclosure: b-responsive-server-side-request-forgery-ssrf-b-bhmth

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'bhmth'Link to Submitters Profile:https://hackerone.com/b'bhmth' Report Title:b'Responsive Server-side Request Forgery (SSRF)'Report Link:https://hackerone.com/reports/1895874Date Submitted:19...

HackerOne Bug Bounty Disclosure: b-html-injection-at-company-name-or-product-name-and-can-be-shown-on-contact-sales-form-b-domg

Company Name: b'LinkedIn' Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b'domg'Link to Submitters Profile:https://hackerone.com/b'domg' Report Title:b'HTML injection at Company Name or Product...

HackerOne Bug Bounty Disclosure: b-critical-curl-cve-vulnerability-code-changes-are-disclosed-on-the-internet-b-shelldoit

Company Name: b'curl' Company HackerOne URL: https://hackerone.com/curl Submitted By:b'shelldoit'Link to Submitters Profile:https://hackerone.com/b'shelldoit' Report Title:b' Curl CVE-2023-38545 vulnerability code changes are...

HackerOne Bug Bounty Disclosure: b-inviting-excessive-long-email-addresses-to-a-calendar-event-makes-the-server-unresponsive-b-shuvam

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'shuvam321'Link to Submitters Profile:https://hackerone.com/b'shuvam321' Report Title:b'Inviting excessive long email addresses to a...

HackerOne Bug Bounty Disclosure: b-exposing-django-debug-panel-and-sensitive-infrastructure-information-at-https-dev-fxprivaterelay-nonprod-cloudops-mozgcp-net-b-aliend

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'aliend89'Link to Submitters Profile:https://hackerone.com/b'aliend89' Report Title:b'Exposing Django Debug Panel and...

HackerOne Bug Bounty Disclosure: b-potential-spoofing-risk-through-firefox-private-relay-service-b-nicholas-cw

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'nicholas_cw'Link to Submitters Profile:https://hackerone.com/b'nicholas_cw' Report Title:b'Potential Spoofing Risk through Firefox...

HackerOne Bug Bounty Disclosure: b-subdomain-takeover-on-one-of-the-subdomain-under-mozaws-net-b-holybugx

Company Name: b'Mozilla Core Services' Company HackerOne URL: https://hackerone.com/mozilla_core_services Submitted By:b'holybugx'Link to Submitters Profile:https://hackerone.com/b'holybugx' Report Title:b'Subdomain takeover on one of...

HackerOne Bug Bounty Disclosure: b-admin-mytva-com-customer-lookup-and-internal-notes-bypass-b-itssixtynein

Company Name: b'Tennessee Valley Authority' Company HackerOne URL: https://hackerone.com/tennessee-valley-authority Submitted By:b'itssixtynein'Link to Submitters Profile:https://hackerone.com/b'itssixtynein' Report Title:b'Admin.MyTVA.com Customer lookup and internal...