Bug Bounty

HackerOne Bug Bounty Disclosure: idor-vulnerability-leads-to-deleting-message-after-leaving-getting-banned-from-group-using-message-id-yash

Company Name: Rocket.Chat Company HackerOne URL: https://hackerone.com/rocket_chat Submitted By:yash24Link to Submitters Profile:https://hackerone.com/yash24 Report Title:IDOR vulnerability leads to Deleting message after...

HackerOne Bug Bounty Disclosure: dos-taking-down-a-k-users-gitlab-ee-instance-or-multiple-sidekiq-instances-by-importing-a-malicious-repo-from-a-github-ee-self-hosted-server-a

Company Name: GitLab Company HackerOne URL: https://hackerone.com/gitlab Submitted By:a92847865Link to Submitters Profile:https://hackerone.com/a92847865 Report Title:DOS: taking down a 1k users Gitlab...

HackerOne Bug Bounty Disclosure: user-api-key-leakage-in-github-commit-leads-to-unauthorized-access-to-sql-telemetry-mozilla-org-anhchangmutrang

Company Name: Mozilla Company HackerOne URL: https://hackerone.com/mozilla Submitted By:anhchangmutrangLink to Submitters Profile:https://hackerone.com/anhchangmutrang Report Title:User API Key leakage in Github commit...

HackerOne Bug Bounty Disclosure: html-injection-possible-with-soft-email-confirmations-when-administrator-manually-confirms-attacker-email-address-cryptopone

Company Name: GitLab Company HackerOne URL: https://hackerone.com/gitlab Submitted By:cryptoponeLink to Submitters Profile:https://hackerone.com/cryptopone Report Title:HTML injection possible with soft email confirmations...

HackerOne Bug Bounty Disclosure: reflected-xss-in-hxxps-nin-mtn-ng-nin-success-message-lol-nin-vulnerable-hazemhussien

Company Name: MTN Group Company HackerOne URL: https://hackerone.com/mtn_group Submitted By:hazemhussien99Link to Submitters Profile:https://hackerone.com/hazemhussien99 Report Title:Reflected XSS in hXXps://ninmtnng/nin/success?message=lol&nin=Report Link:https://hackerone.com/reports/2039384Date Submitted:05...

HackerOne Bug Bounty Disclosure: external-service-interaction-http-hesham-elsheme

Company Name: AWS VDP Company HackerOne URL: https://hackerone.com/aws_vdp Submitted By:hesham_elshemeLink to Submitters Profile:https://hackerone.com/hesham_elsheme Report Title:External service interaction (HTTP)Report Link:https://hackerone.com/reports/2731133Date Submitted:04...

HackerOne Bug Bounty Disclosure: the-initial-e-ee-password-generated-by-rocket-chat-mobile-can-be-recovered-in-a-practical-timescale-h

Company Name: Rocket.Chat Company HackerOne URL: https://hackerone.com/rocket_chat Submitted By:h0011Link to Submitters Profile:https://hackerone.com/h0011 Report Title:The initial E2EE password generated by RocketChat...

HackerOne Bug Bounty Disclosure: -switch-pia-mk-dx-stack-buffer-overflow-and-potential-rce-in-pia-lan-ldn-possibly-nex-room-info-deserialization-regginator

Company Name: Nintendo Company HackerOne URL: https://hackerone.com/nintendo Submitted By:regginatorLink to Submitters Profile:https://hackerone.com/regginator Report Title: Stack buffer overflow and potential RCE...