bug bounty

HackerOne Bug Bounty Disclosure: b-cross-origin-resource-sharing-arbitrary-origin-trusted-b-kalendra

Company Name: b'Radancy' Company HackerOne URL: https://hackerone.com/radancy Submitted By:b'kalendra456'Link to Submitters Profile:https://hackerone.com/b'kalendra456' Report Title:b'Cross-origin resource sharing: arbitrary origin trusted'Report Link:https://hackerone.com/reports/1848730Date...

HackerOne Bug Bounty Disclosure: b-insecure-storage-of-information-you-can-view-any-file-uploaded-to-the-server-without-authentication-and-only-with-a-single-link-b-h

Company Name: b'Radancy' Company HackerOne URL: https://hackerone.com/radancy Submitted By:b'h03'Link to Submitters Profile:https://hackerone.com/b'h03' Report Title:b'insecure storage of information, you can view...

HackerOne Bug Bounty Disclosure: b-mk-dx-improper-metadata-parsing-b-crazy-man

Company Name: b'Nintendo' Company HackerOne URL: https://hackerone.com/nintendo Submitted By:b'crazy_man123'Link to Submitters Profile:https://hackerone.com/b'crazy_man123' Report Title:b' Improper metadata parsing'Report Link:https://hackerone.com/reports/1688309Date Submitted:17 August...

HackerOne Bug Bounty Disclosure: b-mk-dx-improper-metadata-validation-b-crazy-man

Company Name: b'Nintendo' Company HackerOne URL: https://hackerone.com/nintendo Submitted By:b'crazy_man123'Link to Submitters Profile:https://hackerone.com/b'crazy_man123' Report Title:b' Improper metadata validation 2'Report Link:https://hackerone.com/reports/1812732Date Submitted:17...

HackerOne Bug Bounty Disclosure: b-renaming-aliasing-relative-symbolic-links-potentially-redirects-them-to-supposedly-inaccessible-locations-b-tniessen

Company Name: b'Node.js' Company HackerOne URL: https://hackerone.com/nodejs Submitted By:b'tniessen'Link to Submitters Profile:https://hackerone.com/b'tniessen' Report Title:b'Renaming/aliasing relative symbolic links potentially redirects them...

HackerOne Bug Bounty Disclosure: b-path-traversal-allows-tricking-the-talk-android-app-into-writing-files-into-it-s-root-directory-b-fr-via

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'fr4via'Link to Submitters Profile:https://hackerone.com/b'fr4via' Report Title:b"Path traversal allows tricking the Talk Android...

HackerOne Bug Bounty Disclosure: b-html-injection-on-newsroom-snap-com-via-search-q-b-jotita

Company Name: b'Snapchat' Company HackerOne URL: https://hackerone.com/snapchat Submitted By:b'jotita3'Link to Submitters Profile:https://hackerone.com/b'jotita3' Report Title:b'HTML injection on newsroom.snap.com/* via search?q=1'Report Link:https://hackerone.com/reports/2018615Date...

HackerOne Bug Bounty Disclosure: b-hackerone-support-system-doesn-t-require-any-authentication-may-lead-unauthorized-action-b-rafsanzami

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'rafsanzami'Link to Submitters Profile:https://hackerone.com/b'rafsanzami' Report Title:b"HackerOne Support System Doesn't Require Any Authentication...

HackerOne Bug Bounty Disclosure: b-hackerone-all-private-program-name-leaked-to-public-via-collaborator-or-attacker-can-easily-dump-all-private-program-names-through-collaborator-b-hackit-bharat

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'hackit_bharat'Link to Submitters Profile:https://hackerone.com/b'hackit_bharat' Report Title:b'Hackerone All Private Program Name Leaked to...

HackerOne Bug Bounty Disclosure: b-nginx-alias-traversal-babel-bluetab-net-b-dk-trin

Company Name: b'IBM' Company HackerOne URL: https://hackerone.com/ibm Submitted By:b'dk4trin'Link to Submitters Profile:https://hackerone.com/b'dk4trin' Report Title:b'Nginx Alias Traversal - babel.bluetab.net'Report Link:https://hackerone.com/reports/2061826Date Submitted:11...

HackerOne Bug Bounty Disclosure: b-create-miscellaneous-support-ticket-on-anyone-s-account-through-support-hackerone-com-email-b-sayaanalam

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'sayaanalam'Link to Submitters Profile:https://hackerone.com/b'sayaanalam' Report Title:b"Create miscellaneous support ticket on anyone's account...

HackerOne Bug Bounty Disclosure: b-permission-model-bypass-by-specifying-a-path-traversal-sequence-in-a-buffer-b-haxatron

Company Name: b'Node.js' Company HackerOne URL: https://hackerone.com/nodejs Submitted By:b'haxatron1'Link to Submitters Profile:https://hackerone.com/b'haxatron1' Report Title:b'Permission model bypass by specifying a path...

HackerOne Bug Bounty Disclosure: b-fs-mkdtemp-and-fs-mkdtempsync-are-missing-getvalidatedpath-checks-b-haxatron

Company Name: b'Node.js' Company HackerOne URL: https://hackerone.com/nodejs Submitted By:b'haxatron1'Link to Submitters Profile:https://hackerone.com/b'haxatron1' Report Title:b'fs.mkdtemp() and fs.mkdtempSync() are missing getValidatedPath() checks.'Report...

HackerOne Bug Bounty Disclosure: b-node-reads-openssl-cnf-from-home-iojs-build-upon-startup-b-msvrmiscovet

Company Name: b'Node.js' Company HackerOne URL: https://hackerone.com/nodejs Submitted By:b'msvrmiscovet'Link to Submitters Profile:https://hackerone.com/b'msvrmiscovet' Report Title:b'Node 18 reads openssl.cnf from /home/iojs/build/... upon...