HackerOne Bug Bounty Disclosure: steal-any-user-in-your-orgs-private-github-token-by-pointing-the-gh-integration-at-an-attacker-controlled-ghe-instance-archangel

Company Name:
New Relic

Company HackerOne URL:
https://hackerone.com/newrelic

Submitted By:
archangel

Link to Submitters Profile:
https://hackerone.com/archangel

Report Title:
Steal any user in your orgs private GitHub token by pointing the GH integration at an attacker controlled GHE instance

Report Link:
https://hackerone.com/reports/1195807

Date Submitted:
19 March 2024

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.