bug bounty

HackerOne Bug Bounty Disclosure: b-policy-restricted-modules-can-escalate-to-higher-privileges-by-impersonating-other-modules-in-a-policy-list-using-module-constructor-createrequire-b-haxatron

Company Name: b'Node.js' Company HackerOne URL: https://hackerone.com/nodejs Submitted By:b'haxatron1'Link to Submitters Profile:https://hackerone.com/b'haxatron1' Report Title:b'Policy-restricted modules can escalate to higher privileges...

HackerOne Bug Bounty Disclosure: b-improper-restriction-of-excessive-authentication-attempts-on-webdav-endpoint-b-unknownsh

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'unknownsh'Link to Submitters Profile:https://hackerone.com/b'unknownsh' Report Title:b'Improper restriction of excessive authentication attempts on...

HackerOne Bug Bounty Disclosure: b-missing-brute-force-protection-on-oauth-api-controller-b-mikaelgundersen

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'mikaelgundersen'Link to Submitters Profile:https://hackerone.com/b'mikaelgundersen' Report Title:b'Missing brute force protection on OAuth2 API...

HackerOne Bug Bounty Disclosure: b-new-apppassword-can-be-generated-without-password-confirmation-b-mikaelgundersen

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'mikaelgundersen'Link to Submitters Profile:https://hackerone.com/b'mikaelgundersen' Report Title:b'New AppPassword can be generated without password...

HackerOne Bug Bounty Disclosure: b-any-non-admin-user-from-an-instance-can-destroy-any-user-and-or-global-external-filesystem-b-cult

Company Name: b'Nextcloud' Company HackerOne URL: https://hackerone.com/nextcloud Submitted By:b'cult'Link to Submitters Profile:https://hackerone.com/b'cult' Report Title:b'Any (non-admin) user from an instance can...

HackerOne Bug Bounty Disclosure: b-usernames-still-visible-on-report-export-pdf-despite-i-want-to-redact-all-usernames-is-selected-b-japz

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'japz'Link to Submitters Profile:https://hackerone.com/b'japz' Report Title:b'Usernames still visible on report export pdf...

HackerOne Bug Bounty Disclosure: b-operation-createorupdateso-lineupmutation-does-not-restrict-multiple-captains-b-fixenet

Company Name: b'Sorare' Company HackerOne URL: https://hackerone.com/sorare Submitted By:b'fixenet'Link to Submitters Profile:https://hackerone.com/b'fixenet' Report Title:b'Operation CreateOrUpdateSo5LineupMutation does not restrict multiple captains'Report...

HackerOne Bug Bounty Disclosure: b-smuggling-content-in-pr-with-refs-replace-in-github-b-inspector-ambitious

Company Name: b'GitHub' Company HackerOne URL: https://hackerone.com/github Submitted By:b'inspector-ambitious'Link to Submitters Profile:https://hackerone.com/b'inspector-ambitious' Report Title:b'Smuggling content in PR with refs/replace in...

HackerOne Bug Bounty Disclosure: b-apache-mod-negotiation-filename-bruteforcing-https-api-ratelimited-me-b-codeslayer

Company Name: b'RATELIMITED' Company HackerOne URL: https://hackerone.com/ratelimited Submitted By:b'codeslayer137'Link to Submitters Profile:https://hackerone.com/b'codeslayer137' Report Title:b'Apache mod_negotiation filename bruteforcing https://api.ratelimited.me'Report Link:https://hackerone.com/reports/475167Date Submitted:01...

HackerOne Bug Bounty Disclosure: b-bypass-two-factor-authentication-b-spaceboy

Company Name: b'LinkedIn' Company HackerOne URL: https://hackerone.com/linkedin Submitted By:b'spaceboy20'Link to Submitters Profile:https://hackerone.com/b'spaceboy20' Report Title:b'bypass two-factor authentication.'Report Link:https://hackerone.com/reports/1842183Date Submitted:01 August 2023...

HackerOne Bug Bounty Disclosure: b-disavowed-an-email-without-any-authentication-b-sameersec

Company Name: b'Liberapay' Company HackerOne URL: https://hackerone.com/liberapay Submitted By:b'sameersec'Link to Submitters Profile:https://hackerone.com/b'sameersec' Report Title:b'Disavowed an email without any authentication'Report Link:https://hackerone.com/reports/2088808Date...

HackerOne Bug Bounty Disclosure: b-takeover-of-hackerone-engineering-via-github-b-m-chan

Company Name: b'HackerOne' Company HackerOne URL: https://hackerone.com/security Submitted By:b'm0chan'Link to Submitters Profile:https://hackerone.com/b'm0chan' Report Title:b'Takeover of hackerone.engineering via Github'Report Link:https://hackerone.com/reports/2085260Date Submitted:31...

HackerOne Bug Bounty Disclosure: b-crash-report-cloudflare-warp-doesn-t-verify-text-length-in-excluded-host-name-input-data-b-shewhoisblack

Company Name: b'Cloudflare Public Bug Bounty' Company HackerOne URL: https://hackerone.com/cloudflare Submitted By:b'shewhoisblack'Link to Submitters Profile:https://hackerone.com/b'shewhoisblack' Report Title:b'Crash report -Cloudflare WARP...

HackerOne Bug Bounty Disclosure: b-csrf-in-seller-us-tiktok-com-profile-account-setting-delegation-login-b-eye

Company Name: b'TikTok' Company HackerOne URL: https://hackerone.com/tiktok Submitted By:b'eye_'Link to Submitters Profile:https://hackerone.com/b'eye_' Report Title:b'CSRF in seller-us.tiktok.com/profile/account-setting/delegation-login 'Report Link:https://hackerone.com/reports/2002352Date Submitted:26 July...

HackerOne Bug Bounty Disclosure: heap-buffer-overflow-in-gc-writebarrier-incremental-piao

Company Name: Ruby Company HackerOne URL: https://hackerone.com/ruby Submitted By:piaoLink to Submitters Profile:https://hackerone.com/piao Report Title:heap-buffer-overflow in gc_writebarrier_incrementalReport Link:https://hackerone.com/reports/1940002Date Submitted:19 July 2023...