Stored XSS at APM transaction map (transactionName field)
π https://hackerone.com/reports/667770
πΉ Severity: Medium | π° 2,500 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 1:48pm (UTC)
π https://hackerone.com/reports/667770
πΉ Severity: Medium | π° 2,500 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 1:48pm (UTC)
One Click Remote Code Injection - *.blog.newrelic.com
π https://hackerone.com/reports/941421
πΉ Severity: Medium | π° 506 USD
πΉ Reported To: New Relic
πΉ Reported By: #arsene_lupin
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:14pm (UTC)
π https://hackerone.com/reports/941421
πΉ Severity: Medium | π° 506 USD
πΉ Reported To: New Relic
πΉ Reported By: #arsene_lupin
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:14pm (UTC)
Secure credentials values disclosure to regular users due to access control issue in monitor creating function
π https://hackerone.com/reports/788499
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:19pm (UTC)
π https://hackerone.com/reports/788499
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:19pm (UTC)
Attacker can create new account inside any partnership with no approve from the Partnership owner
π https://hackerone.com/reports/786109
πΉ Severity: Medium | π° 695 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:26pm (UTC)
π https://hackerone.com/reports/786109
πΉ Severity: Medium | π° 695 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:26pm (UTC)
Stored XSS at Synthetics private locations (planted through location label or description)
π https://hackerone.com/reports/680240
πΉ Severity: High | π° 2,500 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:29pm (UTC)
π https://hackerone.com/reports/680240
πΉ Severity: High | π° 2,500 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:29pm (UTC)
Restricted user can manage the NerdGraph entities' tags
π https://hackerone.com/reports/757957
πΉ Severity: Medium | π° 750 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:30pm (UTC)
π https://hackerone.com/reports/757957
πΉ Severity: Medium | π° 750 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:30pm (UTC)
Cross-account reading of Insights dashboards through GraphQL
π https://hackerone.com/reports/765565
πΉ Severity: Medium | π° 1,500 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:36pm (UTC)
π https://hackerone.com/reports/765565
πΉ Severity: Medium | π° 1,500 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:36pm (UTC)
Ability to buy PRO subscriptions by arbitrary reduced prices
π https://hackerone.com/reports/783688
πΉ Severity: Low | π° 203 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:37pm (UTC)
π https://hackerone.com/reports/783688
πΉ Severity: Low | π° 203 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:37pm (UTC)
Account owner/admin can't actually delete personal users' API keys
π https://hackerone.com/reports/782703
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:38pm (UTC)
π https://hackerone.com/reports/782703
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:38pm (UTC)
Restricted user can update Apdex target for applications by leveraging the GraphQL mutation
π https://hackerone.com/reports/776449
πΉ Severity: Medium | π° 626 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:39pm (UTC)
π https://hackerone.com/reports/776449
πΉ Severity: Medium | π° 626 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:39pm (UTC)
Restricted user can remove NerdStorage documents/collections scoped to ACCOUNT or ENTITY
π https://hackerone.com/reports/766145
πΉ Severity: Medium | π° 600 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:40pm (UTC)
π https://hackerone.com/reports/766145
πΉ Severity: Medium | π° 600 USD
πΉ Reported To: New Relic
πΉ Reported By: #skavans
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 3:40pm (UTC)
Restricted user can add and delete tags of APM key transactions
π https://hackerone.com/reports/638685
πΉ Severity: Medium | π° 750 USD
πΉ Reported To: New Relic
πΉ Reported By: #jon_bottarini
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 4:39pm (UTC)
π https://hackerone.com/reports/638685
πΉ Severity: Medium | π° 750 USD
πΉ Reported To: New Relic
πΉ Reported By: #jon_bottarini
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 4:39pm (UTC)
IDOR allows accounts to view full name of other accounts based on email through share notes feature
π https://hackerone.com/reports/476958
πΉ Severity: Medium | π° 750 USD
πΉ Reported To: New Relic
πΉ Reported By: #jon_bottarini
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 4:40pm (UTC)
π https://hackerone.com/reports/476958
πΉ Severity: Medium | π° 750 USD
πΉ Reported To: New Relic
πΉ Reported By: #jon_bottarini
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 4:40pm (UTC)
Bypass of #447975 - view mobile application token though "Application Information" sidebar on Installation page
π https://hackerone.com/reports/479139
πΉ Severity: Low | π° 500 USD
πΉ Reported To: New Relic
πΉ Reported By: #jon_bottarini
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 4:40pm (UTC)
π https://hackerone.com/reports/479139
πΉ Severity: Low | π° 500 USD
πΉ Reported To: New Relic
πΉ Reported By: #jon_bottarini
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 4:40pm (UTC)
https://βββββ is vulnerable to CVE-2020-3452 Read-Only Path Traversal Vulnerability
π https://hackerone.com/reports/940384
πΉ Severity: High
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #they
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 6:08pm (UTC)
π https://hackerone.com/reports/940384
πΉ Severity: High
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #they
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 6:08pm (UTC)
Path traversal on https://βββ allows arbitrary file read (CVE-2020-3452)
π https://hackerone.com/reports/936399
πΉ Severity: High
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #un4gi
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 6:09pm (UTC)
π https://hackerone.com/reports/936399
πΉ Severity: High
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #un4gi
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 6:09pm (UTC)
Remote Code Execution via CVE-2019-18935
π https://hackerone.com/reports/913695
πΉ Severity: Critical
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #un4gi
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 6:11pm (UTC)
π https://hackerone.com/reports/913695
πΉ Severity: Critical
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #un4gi
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 6:11pm (UTC)
Stored XSS Via NRQL chartbuilder JSON view
π https://hackerone.com/reports/634692
πΉ Severity: High | π° 2,500 USD
πΉ Reported To: New Relic
πΉ Reported By: #jon_bottarini
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 6:56pm (UTC)
π https://hackerone.com/reports/634692
πΉ Severity: High | π° 2,500 USD
πΉ Reported To: New Relic
πΉ Reported By: #jon_bottarini
πΉ State: π’ Resolved
πΉ Disclosed: August 13, 2020, 6:56pm (UTC)
Missing memory corruption protection on Windows release built
π https://hackerone.com/reports/380102
πΉ Severity: Medium | π° 50 USD
πΉ Reported To: Nextcloud
πΉ Reported By: #secconsult
πΉ State: π’ Resolved
πΉ Disclosed: August 14, 2020, 6:21am (UTC)
π https://hackerone.com/reports/380102
πΉ Severity: Medium | π° 50 USD
πΉ Reported To: Nextcloud
πΉ Reported By: #secconsult
πΉ State: π’ Resolved
πΉ Disclosed: August 14, 2020, 6:21am (UTC)
Default Creds Spring Boot Admin
π https://hackerone.com/reports/954818
πΉ Severity: High
πΉ Reported To: 8x8
πΉ Reported By: #testingforbugs
πΉ State: π’ Resolved
πΉ Disclosed: August 14, 2020, 5:01pm (UTC)
π https://hackerone.com/reports/954818
πΉ Severity: High
πΉ Reported To: 8x8
πΉ Reported By: #testingforbugs
πΉ State: π’ Resolved
πΉ Disclosed: August 14, 2020, 5:01pm (UTC)
Arbitrary code execution via untrusted schemas in ajv
π https://hackerone.com/reports/897974
πΉ Severity: Low
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #chalker
πΉ State: π’ Resolved
πΉ Disclosed: August 14, 2020, 5:21pm (UTC)
π https://hackerone.com/reports/897974
πΉ Severity: Low
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #chalker
πΉ State: π’ Resolved
πΉ Disclosed: August 14, 2020, 5:21pm (UTC)