CVE-2022-38362: Apache Airflow Docker Provider <3.0 RCE vulnerability in example dag
π https://hackerone.com/reports/1671140
πΉ Severity: High | π° 4,000 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #happyhacking123
πΉ State: π’ Resolved
πΉ Disclosed: September 23, 2022, 5:16pm (UTC)
π https://hackerone.com/reports/1671140
πΉ Severity: High | π° 4,000 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #happyhacking123
πΉ State: π’ Resolved
πΉ Disclosed: September 23, 2022, 5:16pm (UTC)
CVE-2022-35948: CRLF Injection in Nodejs βundiciβ via Content-Type
π https://hackerone.com/reports/1664019
πΉ Severity: Medium | π° 600 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #happyhacking123
πΉ State: π’ Resolved
πΉ Disclosed: September 23, 2022, 5:38pm (UTC)
π https://hackerone.com/reports/1664019
πΉ Severity: Medium | π° 600 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #happyhacking123
πΉ State: π’ Resolved
πΉ Disclosed: September 23, 2022, 5:38pm (UTC)
π1
[CVE-2022-35949]: undici.request vulnerable to SSRF using absolute / protocol-relative URL on pathname
π https://hackerone.com/reports/1663788
πΉ Severity: Medium | π° 1,200 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #haxatron1
πΉ State: π’ Resolved
πΉ Disclosed: September 23, 2022, 5:51pm (UTC)
π https://hackerone.com/reports/1663788
πΉ Severity: Medium | π° 1,200 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #haxatron1
πΉ State: π’ Resolved
πΉ Disclosed: September 23, 2022, 5:51pm (UTC)
Reflected xss on videostore.mtnonline.com
π https://hackerone.com/reports/1646248
πΉ Severity: High
πΉ Reported To: MTN Group
πΉ Reported By: #possowski
πΉ State: π’ Resolved
πΉ Disclosed: September 25, 2022, 7:10pm (UTC)
π https://hackerone.com/reports/1646248
πΉ Severity: High
πΉ Reported To: MTN Group
πΉ Reported By: #possowski
πΉ State: π’ Resolved
πΉ Disclosed: September 25, 2022, 7:10pm (UTC)
Main Domain Takeover at https://www.marketo.net/
π https://hackerone.com/reports/1661914
πΉ Severity: Critical
πΉ Reported To: Adobe
πΉ Reported By: #gdattacker
πΉ State: π’ Resolved
πΉ Disclosed: September 26, 2022, 3:05pm (UTC)
π https://hackerone.com/reports/1661914
πΉ Severity: Critical
πΉ Reported To: Adobe
πΉ Reported By: #gdattacker
πΉ State: π’ Resolved
πΉ Disclosed: September 26, 2022, 3:05pm (UTC)
XSS Reflected on reddit.com via url path
π https://hackerone.com/reports/1051373
πΉ Severity: High | π° 5,000 USD
πΉ Reported To: Reddit
πΉ Reported By: #criptex
πΉ State: π’ Resolved
πΉ Disclosed: September 27, 2022, 4:04pm (UTC)
π https://hackerone.com/reports/1051373
πΉ Severity: High | π° 5,000 USD
πΉ Reported To: Reddit
πΉ Reported By: #criptex
πΉ State: π’ Resolved
πΉ Disclosed: September 27, 2022, 4:04pm (UTC)
insecure gitlab repositories at ββββββββ [HtUS]
π https://hackerone.com/reports/1624152
πΉ Severity: High | π° 500 USD
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #thpless
πΉ State: π’ Resolved
πΉ Disclosed: September 27, 2022, 6:18pm (UTC)
π https://hackerone.com/reports/1624152
πΉ Severity: High | π° 500 USD
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #thpless
πΉ State: π’ Resolved
πΉ Disclosed: September 27, 2022, 6:18pm (UTC)
password field autocomplete enabled
π https://hackerone.com/reports/1023773
πΉ Severity: Medium
πΉ Reported To: Yelp
πΉ Reported By: #er_salil
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 27, 2022, 11:26pm (UTC)
π https://hackerone.com/reports/1023773
πΉ Severity: Medium
πΉ Reported To: Yelp
πΉ Reported By: #er_salil
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 27, 2022, 11:26pm (UTC)
CORS Misconfiguration on Yelp
π https://hackerone.com/reports/1707616
πΉ Severity: Medium
πΉ Reported To: Yelp
πΉ Reported By: #qualwin3001
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 28, 2022, 3:43am (UTC)
π https://hackerone.com/reports/1707616
πΉ Severity: Medium
πΉ Reported To: Yelp
πΉ Reported By: #qualwin3001
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 28, 2022, 3:43am (UTC)
Directory Listing vulnerability on β.packet8.net/php/include/
π https://hackerone.com/reports/790846
πΉ Severity: Low
πΉ Reported To: 8x8
πΉ Reported By: #rajauzairabdullah
πΉ State: π’ Resolved
πΉ Disclosed: September 28, 2022, 4:41am (UTC)
π https://hackerone.com/reports/790846
πΉ Severity: Low
πΉ Reported To: 8x8
πΉ Reported By: #rajauzairabdullah
πΉ State: π’ Resolved
πΉ Disclosed: September 28, 2022, 4:41am (UTC)
Server-side request forgery (ssrf)
π https://hackerone.com/reports/1712240
πΉ Severity: Medium
πΉ Reported To: Yelp
πΉ Reported By: #raja404
πΉ State: π΄ N/A
πΉ Disclosed: September 28, 2022, 7:54am (UTC)
π https://hackerone.com/reports/1712240
πΉ Severity: Medium
πΉ Reported To: Yelp
πΉ Reported By: #raja404
πΉ State: π΄ N/A
πΉ Disclosed: September 28, 2022, 7:54am (UTC)
DNS rebinding in --inspect (insufficient fix of CVE-2022-32212 affecting macOS devices)
π https://hackerone.com/reports/1632921
πΉ Severity: High
πΉ Reported To: Node.js
πΉ Reported By: #zeyu2001
πΉ State: π’ Resolved
πΉ Disclosed: September 28, 2022, 8:38am (UTC)
π https://hackerone.com/reports/1632921
πΉ Severity: High
πΉ Reported To: Node.js
πΉ Reported By: #zeyu2001
πΉ State: π’ Resolved
πΉ Disclosed: September 28, 2022, 8:38am (UTC)
Take over subdomains of r2.dev using R2 custom domains
π https://hackerone.com/reports/1700276
πΉ Severity: Medium | π° 1,125 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #albertspedersen
πΉ State: π’ Resolved
πΉ Disclosed: September 28, 2022, 12:49pm (UTC)
π https://hackerone.com/reports/1700276
πΉ Severity: Medium | π° 1,125 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #albertspedersen
πΉ State: π’ Resolved
πΉ Disclosed: September 28, 2022, 12:49pm (UTC)
CSV export/import functionality allows administrators to modify member and message content of a workspace
π https://hackerone.com/reports/1661310
πΉ Severity: No Rating | π° 250 USD
πΉ Reported To: Slack
πΉ Reported By: #security_warrior
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 28, 2022, 8:30pm (UTC)
π https://hackerone.com/reports/1661310
πΉ Severity: No Rating | π° 250 USD
πΉ Reported To: Slack
πΉ Reported By: #security_warrior
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 28, 2022, 8:30pm (UTC)
XSS in Widget Review Form Preview in settings
π https://hackerone.com/reports/1595905
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: Judge.me
πΉ Reported By: #penguinshelp
πΉ State: π’ Resolved
πΉ Disclosed: September 29, 2022, 8:35am (UTC)
π https://hackerone.com/reports/1595905
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: Judge.me
πΉ Reported By: #penguinshelp
πΉ State: π’ Resolved
πΉ Disclosed: September 29, 2022, 8:35am (UTC)
no rate limit in forgot password session
π https://hackerone.com/reports/1714970
πΉ Severity: Medium
πΉ Reported To: Yelp
πΉ Reported By: #irfadps
πΉ State: π΄ N/A
πΉ Disclosed: September 29, 2022, 6:17pm (UTC)
π https://hackerone.com/reports/1714970
πΉ Severity: Medium
πΉ Reported To: Yelp
πΉ Reported By: #irfadps
πΉ State: π΄ N/A
πΉ Disclosed: September 29, 2022, 6:17pm (UTC)
Open Redirect
π https://hackerone.com/reports/1581258
πΉ Severity: Low | π° 258 USD
πΉ Reported To: Flickr
πΉ Reported By: #stevejubs
πΉ State: π’ Resolved
πΉ Disclosed: September 29, 2022, 10:51pm (UTC)
π https://hackerone.com/reports/1581258
πΉ Severity: Low | π° 258 USD
πΉ Reported To: Flickr
πΉ Reported By: #stevejubs
πΉ State: π’ Resolved
πΉ Disclosed: September 29, 2022, 10:51pm (UTC)
Password Policy Restriction Bypass
π https://hackerone.com/reports/1675730
πΉ Severity: Low | π° 250 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #lohigowda
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 8:50am (UTC)
π https://hackerone.com/reports/1675730
πΉ Severity: Low | π° 250 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #lohigowda
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 8:50am (UTC)
Lack of Packet Sanitation in Goflow Results in Multiple DoS Attack Vectors and Bugs
π https://hackerone.com/reports/1636320
πΉ Severity: High | π° 500 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #path_network
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 11:15am (UTC)
π https://hackerone.com/reports/1636320
πΉ Severity: High | π° 500 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #path_network
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 11:15am (UTC)
Unrestricted File Upload on reddit.secure.force.com
π https://hackerone.com/reports/1606957
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Reddit
πΉ Reported By: #heckintosh
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 2:56pm (UTC)
π https://hackerone.com/reports/1606957
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Reddit
πΉ Reported By: #heckintosh
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 2:56pm (UTC)