HackerOne Bug Bounty Disclosure: rce-on-worker-host-due-to-unsanitized-env-variable-name-in-task-definition-on-community-tc-services-mozilla-com-ebrietas

Company Name:
Mozilla

Company HackerOne URL:
https://hackerone.com/mozilla

Submitted By:
ebrietas

Link to Submitters Profile:
https://hackerone.com/ebrietas

Report Title:
RCE on worker host due to unsanitized “env” variable name in task definition on community-tc[.]services[.]mozilla[.]com

Report Link:
https://hackerone.com/reports/2221404

Date Submitted:
08 December 2024

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.