damage to the timeline so that comment fields cannot be displayed or not available to all members in the store
π https://hackerone.com/reports/971599
πΉ Severity: No Rating
πΉ Reported To: Shopify
πΉ Reported By: #jaka_tingkir
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2020, 4:45pm (UTC)
π https://hackerone.com/reports/971599
πΉ Severity: No Rating
πΉ Reported To: Shopify
πΉ Reported By: #jaka_tingkir
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2020, 4:45pm (UTC)
Add apps to packages 0, 61, 62 with /store/ajaxpackagemerge
π https://hackerone.com/reports/972243
πΉ Severity: High | π° 2,500 USD
πΉ Reported To: Valve
πΉ Reported By: #njbooher
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2020, 8:07pm (UTC)
π https://hackerone.com/reports/972243
πΉ Severity: High | π° 2,500 USD
πΉ Reported To: Valve
πΉ Reported By: #njbooher
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2020, 8:07pm (UTC)
Unauthorized updates to extended_info properties in /store/ajaxpackagesave
π https://hackerone.com/reports/815547
πΉ Severity: High | π° 2,500 USD
πΉ Reported To: Valve
πΉ Reported By: #njbooher
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2020, 8:27pm (UTC)
π https://hackerone.com/reports/815547
πΉ Severity: High | π° 2,500 USD
πΉ Reported To: Valve
πΉ Reported By: #njbooher
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2020, 8:27pm (UTC)
Stored XSS on PyPi simple API endpoint
π https://hackerone.com/reports/856836
πΉ Severity: Medium | π° 3,000 USD
πΉ Reported To: GitLab
πΉ Reported By: #vakzz
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2020, 9:57pm (UTC)
π https://hackerone.com/reports/856836
πΉ Severity: Medium | π° 3,000 USD
πΉ Reported To: GitLab
πΉ Reported By: #vakzz
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2020, 9:57pm (UTC)
Stored XSS in markdown when redacting references
π https://hackerone.com/reports/836649
πΉ Severity: High | π° 5,000 USD
πΉ Reported To: GitLab
πΉ Reported By: #vakzz
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2020, 9:58pm (UTC)
π https://hackerone.com/reports/836649
πΉ Severity: High | π° 5,000 USD
πΉ Reported To: GitLab
πΉ Reported By: #vakzz
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2020, 9:58pm (UTC)
Smartsheet employees email disclosure through enpoint after login.
π https://hackerone.com/reports/880089
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Smartsheet
πΉ Reported By: #soareswallace
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2020, 10:15pm (UTC)
π https://hackerone.com/reports/880089
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Smartsheet
πΉ Reported By: #soareswallace
πΉ State: π’ Resolved
πΉ Disclosed: September 9, 2020, 10:15pm (UTC)
SSRF at https://cognitive.topcoder.com leads to AWS instance metadata due to vulnerable email subscription feature
π https://hackerone.com/reports/876424
πΉ Severity: Critical
πΉ Reported To: Topcoder
πΉ Reported By: #mase289
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2020, 12:42pm (UTC)
π https://hackerone.com/reports/876424
πΉ Severity: Critical
πΉ Reported To: Topcoder
πΉ Reported By: #mase289
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2020, 12:42pm (UTC)
THX Tuneup Survey feedback disclosure via Google cached content for apps.thx.com
π https://hackerone.com/reports/751729
πΉ Severity: Low | π° 200 USD
πΉ Reported To: Razer
πΉ Reported By: #jackb898
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2020, 4:04pm (UTC)
π https://hackerone.com/reports/751729
πΉ Severity: Low | π° 200 USD
πΉ Reported To: Razer
πΉ Reported By: #jackb898
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2020, 4:04pm (UTC)
bypass the [OKTA] login redirect can lead to disclosing limited-information about the sub-domain at [ shiptsec.com ]
π https://hackerone.com/reports/968699
πΉ Severity: Low | π° 200 USD
πΉ Reported To: Shipt
πΉ Reported By: #tester1231233
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2020, 4:23pm (UTC)
π https://hackerone.com/reports/968699
πΉ Severity: Low | π° 200 USD
πΉ Reported To: Shipt
πΉ Reported By: #tester1231233
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2020, 4:23pm (UTC)
Safe Redirect Bypass
π https://hackerone.com/reports/945990
πΉ Severity: Low | π° 560 USD
πΉ Reported To: Twitter
πΉ Reported By: #cyanpiny
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2020, 4:57pm (UTC)
π https://hackerone.com/reports/945990
πΉ Severity: Low | π° 560 USD
πΉ Reported To: Twitter
πΉ Reported By: #cyanpiny
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2020, 4:57pm (UTC)
Team object in GraphQL disclosed private_comment
π https://hackerone.com/reports/978143
πΉ Severity: Medium | π° 2,500 USD
πΉ Reported To: HackerOne
πΉ Reported By: #haxta4ok00
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2020, 7:05pm (UTC)
π https://hackerone.com/reports/978143
πΉ Severity: Medium | π° 2,500 USD
πΉ Reported To: HackerOne
πΉ Reported By: #haxta4ok00
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2020, 7:05pm (UTC)
Unsafe deserialization in Nexus Repository helm plugin
π https://hackerone.com/reports/917843
πΉ Severity: Critical
πΉ Reported To: Central Security Project
πΉ Reported By: #c0d3p1ut0s
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2020, 10:07pm (UTC)
π https://hackerone.com/reports/917843
πΉ Severity: Critical
πΉ Reported To: Central Security Project
πΉ Reported By: #c0d3p1ut0s
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2020, 10:07pm (UTC)
http request smuggling in pscp.tv and periscope.tv
π https://hackerone.com/reports/713285
πΉ Severity: High | π° 560 USD
πΉ Reported To: Twitter
πΉ Reported By: #protostar0
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2020, 10:52pm (UTC)
π https://hackerone.com/reports/713285
πΉ Severity: High | π° 560 USD
πΉ Reported To: Twitter
πΉ Reported By: #protostar0
πΉ State: π’ Resolved
πΉ Disclosed: September 10, 2020, 10:52pm (UTC)
Blind HTTP GET SSRF via website icon fetch (bypass of pull#812)
π https://hackerone.com/reports/925527
πΉ Severity: Low
πΉ Reported To: Bitwarden
πΉ Reported By: #shielder
πΉ State: π’ Resolved
πΉ Disclosed: September 11, 2020, 1:24pm (UTC)
π https://hackerone.com/reports/925527
πΉ Severity: Low
πΉ Reported To: Bitwarden
πΉ Reported By: #shielder
πΉ State: π’ Resolved
πΉ Disclosed: September 11, 2020, 1:24pm (UTC)
Cache poisoning via X-Forwarded-Host in www.shopify.com/partners/blog
π https://hackerone.com/reports/977851
πΉ Severity: Low | π° 1,000 USD
πΉ Reported To: Shopify
πΉ Reported By: #dakitu
πΉ State: π’ Resolved
πΉ Disclosed: September 11, 2020, 5:03pm (UTC)
π https://hackerone.com/reports/977851
πΉ Severity: Low | π° 1,000 USD
πΉ Reported To: Shopify
πΉ Reported By: #dakitu
πΉ State: π’ Resolved
πΉ Disclosed: September 11, 2020, 5:03pm (UTC)
[keyd] Prototype pollution
π https://hackerone.com/reports/877515
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #d3lla
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 10:51am (UTC)
π https://hackerone.com/reports/877515
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #d3lla
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 10:51am (UTC)
[objtools] Prototype pollution
π https://hackerone.com/reports/878394
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #d3lla
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 10:51am (UTC)
π https://hackerone.com/reports/878394
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #d3lla
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 10:51am (UTC)
[flsaba] Stored XSS in the file and directory name when directories listing
π https://hackerone.com/reports/856588
πΉ Severity: Low
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #d3lla
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 10:52am (UTC)
π https://hackerone.com/reports/856588
πΉ Severity: Low
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #d3lla
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 10:52am (UTC)
Password protection can be removed for newly created development store
π https://hackerone.com/reports/965510
πΉ Severity: No Rating | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #francisbeaudoin
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 6:59pm (UTC)
π https://hackerone.com/reports/965510
πΉ Severity: No Rating | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #francisbeaudoin
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 6:59pm (UTC)
Admin web sessions remain active after logout of Shopify ID
π https://hackerone.com/reports/952035
πΉ Severity: No Rating | π° 1,000 USD
πΉ Reported To: Shopify
πΉ Reported By: #jaka_tingkir
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 6:59pm (UTC)
π https://hackerone.com/reports/952035
πΉ Severity: No Rating | π° 1,000 USD
πΉ Reported To: Shopify
πΉ Reported By: #jaka_tingkir
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 6:59pm (UTC)
XSS / SELF XSS
π https://hackerone.com/reports/906201
πΉ Severity: Low | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #whoami991
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 7:25pm (UTC)
π https://hackerone.com/reports/906201
πΉ Severity: Low | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #whoami991
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 7:25pm (UTC)