Bugpoint
1K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
Ability to see password protected content by bypassing the password page of shopify preview URL for new development stores (as of August 17, 2020)

πŸ‘‰ https://hackerone.com/reports/961929

πŸ”Ή Severity: No Rating | πŸ’° 1,500 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #saltymermaid
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2020, 3:55pm (UTC)
Stored XSS on Broken Themes via filename

πŸ‘‰ https://hackerone.com/reports/406289

πŸ”Ή Severity: Low | πŸ’° 300 USD
πŸ”Ή Reported To: WordPress
πŸ”Ή Reported By: #apapedulimu
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2020, 3:56pm (UTC)
Self XSS in Timeline

πŸ‘‰ https://hackerone.com/reports/854299

πŸ”Ή Severity: No Rating | πŸ’° 500 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #ryat
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2020, 5:04pm (UTC)
Script Editor preview token still working with uninstalled application, even for unpublished script

πŸ‘‰ https://hackerone.com/reports/915940

πŸ”Ή Severity: No Rating | πŸ’° 2,000 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #francisbeaudoin
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2020, 9:34pm (UTC)
[json-bigint] DoS via `__proto__` assignment

πŸ‘‰ https://hackerone.com/reports/916430

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #chalker
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 25, 2020, 10:40pm (UTC)
[min-http-server] List any file in the folder by using path traversal.

πŸ‘‰ https://hackerone.com/reports/569891

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js third-party modules
πŸ”Ή Reported By: #toannc123
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 2:20am (UTC)
Information disclosure to "Permission as auditor" user

πŸ‘‰ https://hackerone.com/reports/959897

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Visma Public
πŸ”Ή Reported By: #risinghunter
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 5:09am (UTC)
[New Relic Infrastructure] Restricted User can still integrate with AWS via forced browsing (plus, a few other bugs)

πŸ‘‰ https://hackerone.com/reports/255685

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 10:51am (UTC)
[NR Synthetics] Restricted user can view synthetics monitors and user permissions through .json endpoint at /permissions/securablemetadata/{GROUP ID}

πŸ‘‰ https://hackerone.com/reports/320689

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 10:54am (UTC)
Adding a new user discloses their full name in the "Users" section of NR Alerts notification channels page

πŸ‘‰ https://hackerone.com/reports/344309

πŸ”Ή Severity: Medium | πŸ’° 1,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 10:57am (UTC)
Internal API endpoint discloses full account name of email address associated with unconfirmed user

πŸ‘‰ https://hackerone.com/reports/332381

πŸ”Ή Severity: Medium | πŸ’° 1,500 USD
πŸ”Ή Reported To: New Relic
πŸ”Ή Reported By: #jon_bottarini
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 10:59am (UTC)
Initial mirror user can be assigned by other user even if the mirror was removed

πŸ‘‰ https://hackerone.com/reports/819821

πŸ”Ή Severity: Medium | πŸ’° 3,000 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #sky003
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 1:52pm (UTC)
Stealing data from customers.gitlab.com without user interaction

πŸ‘‰ https://hackerone.com/reports/674195

πŸ”Ή Severity: High | πŸ’° 3,500 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #rpadovani
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 2:02pm (UTC)
Privilege escalation from any user (including external) to gitlab admin when admin impersonates you

πŸ‘‰ https://hackerone.com/reports/493324

πŸ”Ή Severity: Critical | πŸ’° 10,000 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #skavans
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 2:10pm (UTC)
An attacker can run pipeline jobs as arbitrary user

πŸ‘‰ https://hackerone.com/reports/894569

πŸ”Ή Severity: Critical | πŸ’° 12,000 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #u3mur4
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 2:11pm (UTC)
Stored XSS in "Create Groups"

πŸ‘‰ https://hackerone.com/reports/647130

πŸ”Ή Severity: High | πŸ’° 2,500 USD
πŸ”Ή Reported To: GitLab
πŸ”Ή Reported By: #rioncool22
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 26, 2020, 2:15pm (UTC)
Graphql: Sorting the reports by jira_status field resulted to different value

πŸ‘‰ https://hackerone.com/reports/955286

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: HackerOne
πŸ”Ή Reported By: #0619
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 8:27am (UTC)
Stored XSS in eaccounting.stage.vismaonline.com

πŸ‘‰ https://hackerone.com/reports/897523

πŸ”Ή Severity: Medium | πŸ’° 250 USD
πŸ”Ή Reported To: Visma Public
πŸ”Ή Reported By: #4mat
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 10:26am (UTC)
Null dereference in `cmd_denotify_operation_execute`

πŸ‘‰ https://hackerone.com/reports/965881

πŸ”Ή Severity: No Rating | πŸ’° 50 USD
πŸ”Ή Reported To: Open-Xchange
πŸ”Ή Reported By: #catenacyber
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 11:20am (UTC)
Assert failed in `edit_mail_istream_read`

πŸ‘‰ https://hackerone.com/reports/965790

πŸ”Ή Severity: No Rating | πŸ’° 50 USD
πŸ”Ή Reported To: Open-Xchange
πŸ”Ή Reported By: #catenacyber
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 11:20am (UTC)
Failed assert in `mail_index_transaction_lookup`

πŸ‘‰ https://hackerone.com/reports/965782

πŸ”Ή Severity: No Rating | πŸ’° 50 USD
πŸ”Ή Reported To: Open-Xchange
πŸ”Ή Reported By: #catenacyber
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: August 27, 2020, 11:20am (UTC)