Telegram Web Link
ReDoS in net/http affects webhooks: Sidekiq job stuck at 100% CPU for a year

πŸ‘‰ https://hackerone.com/reports/1531958

πŸ”Ή Severity: Medium | πŸ’° 1,160 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #afewgoats
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 13, 2022, 4:42am (UTC)
No Restriction on password

πŸ‘‰ https://hackerone.com/reports/1696814

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #patronum-m
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: September 13, 2022, 5:02am (UTC)
DOS validator nodes of blockchain to block external connections

πŸ‘‰ https://hackerone.com/reports/1695472

πŸ”Ή Severity: High | πŸ’° 1,500 USD
πŸ”Ή Reported To: Hyperledger
πŸ”Ή Reported By: #cre8
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 13, 2022, 7:56am (UTC)
XSS in http://www.glassdoor.com/Search/results.htm via Parameter Pollution

πŸ‘‰ https://hackerone.com/reports/1632119

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: Glassdoor
πŸ”Ή Reported By: #nokline
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 13, 2022, 1:03pm (UTC)
Web Cache Poisoning leads to XSS and DoS

πŸ‘‰ https://hackerone.com/reports/1621540

πŸ”Ή Severity: High | πŸ’° 1,700 USD
πŸ”Ή Reported To: Glassdoor
πŸ”Ή Reported By: #nokline
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 13, 2022, 1:36pm (UTC)
CSRF in Changing User Verification Email

πŸ‘‰ https://hackerone.com/reports/1531235

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: TikTok
πŸ”Ή Reported By: #f_m
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 13, 2022, 8:30pm (UTC)
Reflected XSS [β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ]

πŸ‘‰ https://hackerone.com/reports/1309386

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #fdeleite
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 1:58pm (UTC)
Abuse cookie-modification, toast HTML and expired domain in CSP-form-action replacing login-page at www.dropbox.com/login to submit creds externally

πŸ‘‰ https://hackerone.com/reports/1590794

πŸ”Ή Severity: High | πŸ’° 6,909 USD
πŸ”Ή Reported To: Dropbox
πŸ”Ή Reported By: #fransrosen
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 3:15pm (UTC)
πŸ”₯1
Shop - Reflected XSS With Clickjacking Leads to Steal User's Cookie In Two Domain

πŸ‘‰ https://hackerone.com/reports/1221942

πŸ”Ή Severity: High
πŸ”Ή Reported To: Meredith
πŸ”Ή Reported By: #error201
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 4:12pm (UTC)
Directory Traversal at β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/1641148

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #0x45
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 8:27pm (UTC)
springboot actuator is leaking internals at β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/1662474

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #thpless
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 8:29pm (UTC)
XSS DUE TO CVE-2022-38463 in https://β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/1681208

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #shuvam321
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 8:30pm (UTC)
IDOR Lead To VIEW & DELETE & Create api_key [HtUS]

πŸ‘‰ https://hackerone.com/reports/1628012

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #bate5a
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 8:32pm (UTC)
SSRF ACCESS AWS METADATA - β–ˆβ–ˆβ–ˆβ–ˆβ–ˆ

πŸ‘‰ https://hackerone.com/reports/1623685

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #0xr3dhunt
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 8:35pm (UTC)
Unprotected β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ and Test site API Exposes Documents, Credentials, and Emails in β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ Proposal System

πŸ‘‰ https://hackerone.com/reports/745171

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #byteone
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 8:40pm (UTC)
Full read SSRF at β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ [HtUS]

πŸ‘‰ https://hackerone.com/reports/1628102

πŸ”Ή Severity: High | πŸ’° 500 USD
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #sudi
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 8:52pm (UTC)
an internel important paths disclosure [HtUS]

πŸ‘‰ https://hackerone.com/reports/1631471

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #ahmed0x0mahmoud
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 8:54pm (UTC)
SSRF in Functional Administrative Support Tool pdf generator (β–ˆβ–ˆβ–ˆβ–ˆ) [HtUS]

πŸ‘‰ https://hackerone.com/reports/1628209

πŸ”Ή Severity: Critical | πŸ’° 4,000 USD
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #codeprivate
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 9:00pm (UTC)
SQL injection at [https://β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ] [HtUS]

πŸ‘‰ https://hackerone.com/reports/1627995

πŸ”Ή Severity: Critical | πŸ’° 1,000 USD
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #malcolmx
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 9:04pm (UTC)
SQL injection at [β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ] [HtUS]

πŸ‘‰ https://hackerone.com/reports/1626198

πŸ”Ή Severity: Critical | πŸ’° 1,000 USD
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #malcolmx
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 9:06pm (UTC)
2025/10/23 09:29:30
Back to Top
HTML Embed Code: