Bugpoint
969 subscribers
3.92K photos
3.92K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Double evaluation in .bash_prompt of dotfiles allows a malicious repository to execute arbitrary commands

πŸ‘‰ https://hackerone.com/reports/1785378

πŸ”Ή Severity: High | πŸ’° 300 USD
πŸ”Ή Reported To: Ian Dunn
πŸ”Ή Reported By: #ryotak
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 1, 2022, 4:00am (UTC)
πŸ”₯2
CVE-2022-45402: Apache Airflow: Open redirect during login

πŸ‘‰ https://hackerone.com/reports/1782514

πŸ”Ή Severity: Medium | πŸ’° 2,400 USD
πŸ”Ή Reported To: Internet Bug Bounty
πŸ”Ή Reported By: #bugra
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 1, 2022, 9:41am (UTC)
Calendar name length not validated before writing to database

πŸ‘‰ https://hackerone.com/reports/1596148

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #errorx404
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 1, 2022, 9:49am (UTC)
Firebase Database Takeover in https://pulseradio.mtn.co.ug/

πŸ‘‰ https://hackerone.com/reports/1447751

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #shuvam321
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 1, 2022, 10:52am (UTC)
😱1
Unprotected Direct Object Reference

πŸ‘‰ https://hackerone.com/reports/1536936

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #coyemerald
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 1, 2022, 5:24pm (UTC)
Remove Every User, Admin, And Owner Out Of Their Teams on developers.mtn.com via IDOR + Information Disclosure

πŸ‘‰ https://hackerone.com/reports/1448550

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #wallotry
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 1, 2022, 5:34pm (UTC)
😱1
Subdomain Takeover at course.oberlo.com

πŸ‘‰ https://hackerone.com/reports/1690951

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #m7mdharoun
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 1, 2022, 7:22pm (UTC)
Read/Write arbitrary (non-HttpOnly) cookies on checkout pages via GoogleAnalyticsAdditionalScripts postMessage handler

πŸ‘‰ https://hackerone.com/reports/1081167

πŸ”Ή Severity: Medium | πŸ’° 1,600 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #bored-engineer
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 1, 2022, 7:34pm (UTC)
Disconnecting an external login provider does not revoke session

πŸ‘‰ https://hackerone.com/reports/1547684

πŸ”Ή Severity: Medium | πŸ’° 1,600 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #attackerbhai
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 1, 2022, 7:50pm (UTC)
Stored XSS in /admin/product and /admin/collections

πŸ‘‰ https://hackerone.com/reports/1147433

πŸ”Ή Severity: Medium | πŸ’° 5,300 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #ashketchum
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 1, 2022, 10:44pm (UTC)
Authentication bypass in https://nin.mtn.ng

πŸ‘‰ https://hackerone.com/reports/1747146

πŸ”Ή Severity: Critical
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #roland_hack
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 2, 2022, 1:00pm (UTC)
XSS in Acronis Cloud Manager Admin Portal

πŸ‘‰ https://hackerone.com/reports/1388788

πŸ”Ή Severity: Medium | πŸ’° 100 USD
πŸ”Ή Reported To: Acronis
πŸ”Ή Reported By: #mooimacow
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 2, 2022, 7:48pm (UTC)
POST following PUT confusion

πŸ‘‰ https://hackerone.com/reports/1752146

πŸ”Ή Severity: Medium | πŸ’° 2,400 USD
πŸ”Ή Reported To: Internet Bug Bounty
πŸ”Ή Reported By: #robbotic
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 2, 2022, 9:03pm (UTC)
Exposed Cortex API at https://cortex-ingest.shopifycloud.com/

πŸ‘‰ https://hackerone.com/reports/1258871

πŸ”Ή Severity: Medium | πŸ’° 6,300 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #ian
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 2, 2022, 10:25pm (UTC)
πŸ‘1
CVE-2022-35260: .netrc parser out-of-bounds access

πŸ‘‰ https://hackerone.com/reports/1753224

πŸ”Ή Severity: Low | πŸ’° 480 USD
πŸ”Ή Reported To: Internet Bug Bounty
πŸ”Ή Reported By: #kurohiro
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 3, 2022, 12:20am (UTC)
πŸ‘1
IDOR in Stats API Endpoint Allows Viewing Equity or Net Profit of Any MT Account

πŸ‘‰ https://hackerone.com/reports/1644436

πŸ”Ή Severity: No Rating | πŸ’° 1,000 USD
πŸ”Ή Reported To: EXNESS
πŸ”Ή Reported By: #ashwarya
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: December 5, 2022, 3:50pm (UTC)
πŸ‘9❀2
[Splatoon 3] Kick other players with NplnLogin message

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Nintendo
πŸ”Ή Reported By: alzxk11
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 2, 2026, 1:25am (UTC)

A vulnerability was discovered that allowed players to kick other players from a Splatoon 3 game using an NplnLogin message.

πŸ‘‰ Read full report
❀1
admin.shopify.com: Shopify Flow continues sending internal emails to a configured recipient after the staff author is removed

πŸ”Ή Severity: None
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: abahack
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: July 3, 2026, 6:50pm (UTC)

πŸ‘‰ Read full report
Any installed app can force immediate logout and persistent DOS of authenticated Basecamp sessions via unprotected exported StartActivity

πŸ”Ή Severity: Medium | πŸ’° 287 USD
πŸ”Ή Weakness: Improper Access Control - Generic
πŸ”Ή Reported To: Basecamp
πŸ”Ή Reported By: zerodaysec_xyz
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 4, 2026, 11:05am (UTC)

A vulnerability was discovered in the Basecamp Android app that allowed any installed app to force immediate logout and persistent denial-of-service of authenticated Basecamp sessions. The vulnerability was due to the `com.basecamp.bc4.app.main.start.StartActivity` being declared as exported without any permission guard. This allowed any app to launch it with an explicit intent, terminating the current session and…

πŸ‘‰ Read full report
OS Command Injection in `aws-cdk-lib` NodejsFunction via Unsanitized `OsCommand` Helper (Supply Chain RCE)

πŸ”Ή Severity: High
πŸ”Ή Weakness: OS Command Injection
πŸ”Ή Reported To: AWS VDP
πŸ”Ή Reported By: kaporia
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 6, 2026, 5:48pm (UTC)

A vulnerability was discovered in the "aws-cdk-lib" NodejsFunction that allowed for OS command injection through the unsanitized "OsCommand" helper. The vulnerability was caused by the lack of proper escaping of user-controlled data when constructing shell commands during Docker-based bundling. This could have potentially led to arbitrary code execution within the Docker container, which had access to the host…

πŸ‘‰ Read full report
Kiro IDE Stores Auth Tokens with World-Readable Permissions (0644)

πŸ”Ή Severity: Medium
πŸ”Ή Weakness: Incorrect Default Permissions
πŸ”Ή Reported To: AWS VDP
πŸ”Ή Reported By: mistercloudsec
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: July 9, 2026, 3:31pm (UTC)

The Kiro IDE (version 0.11.107) wrote authentication tokens (access token and refresh token) to a file with world-readable permissions (0644). The file contained sensitive information, including the access token, refresh token, and profile ARN. This exposed the credentials to potential unauthorized access by local processes or users.

πŸ‘‰ Read full report
πŸ‘1