Blind HTTP GET SSRF via website icon fetch (bypass of pull#812)
π https://hackerone.com/reports/925527
πΉ Severity: Low
πΉ Reported To: Bitwarden
πΉ Reported By: #shielder
πΉ State: π’ Resolved
πΉ Disclosed: September 11, 2020, 1:24pm (UTC)
π https://hackerone.com/reports/925527
πΉ Severity: Low
πΉ Reported To: Bitwarden
πΉ Reported By: #shielder
πΉ State: π’ Resolved
πΉ Disclosed: September 11, 2020, 1:24pm (UTC)
Cache poisoning via X-Forwarded-Host in www.shopify.com/partners/blog
π https://hackerone.com/reports/977851
πΉ Severity: Low | π° 1,000 USD
πΉ Reported To: Shopify
πΉ Reported By: #dakitu
πΉ State: π’ Resolved
πΉ Disclosed: September 11, 2020, 5:03pm (UTC)
π https://hackerone.com/reports/977851
πΉ Severity: Low | π° 1,000 USD
πΉ Reported To: Shopify
πΉ Reported By: #dakitu
πΉ State: π’ Resolved
πΉ Disclosed: September 11, 2020, 5:03pm (UTC)
[keyd] Prototype pollution
π https://hackerone.com/reports/877515
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #d3lla
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 10:51am (UTC)
π https://hackerone.com/reports/877515
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #d3lla
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 10:51am (UTC)
[objtools] Prototype pollution
π https://hackerone.com/reports/878394
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #d3lla
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 10:51am (UTC)
π https://hackerone.com/reports/878394
πΉ Severity: High
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #d3lla
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 10:51am (UTC)
[flsaba] Stored XSS in the file and directory name when directories listing
π https://hackerone.com/reports/856588
πΉ Severity: Low
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #d3lla
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 10:52am (UTC)
π https://hackerone.com/reports/856588
πΉ Severity: Low
πΉ Reported To: Node.js third-party modules
πΉ Reported By: #d3lla
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 10:52am (UTC)
Password protection can be removed for newly created development store
π https://hackerone.com/reports/965510
πΉ Severity: No Rating | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #francisbeaudoin
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 6:59pm (UTC)
π https://hackerone.com/reports/965510
πΉ Severity: No Rating | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #francisbeaudoin
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 6:59pm (UTC)
Admin web sessions remain active after logout of Shopify ID
π https://hackerone.com/reports/952035
πΉ Severity: No Rating | π° 1,000 USD
πΉ Reported To: Shopify
πΉ Reported By: #jaka_tingkir
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 6:59pm (UTC)
π https://hackerone.com/reports/952035
πΉ Severity: No Rating | π° 1,000 USD
πΉ Reported To: Shopify
πΉ Reported By: #jaka_tingkir
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 6:59pm (UTC)
XSS / SELF XSS
π https://hackerone.com/reports/906201
πΉ Severity: Low | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #whoami991
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 7:25pm (UTC)
π https://hackerone.com/reports/906201
πΉ Severity: Low | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #whoami991
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 7:25pm (UTC)
Partner's non-verified business email change reflected into Shopify Collaborator Request
π https://hackerone.com/reports/874574
πΉ Severity: No Rating | π° 1,000 USD
πΉ Reported To: Shopify
πΉ Reported By: #francisbeaudoin
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 7:45pm (UTC)
π https://hackerone.com/reports/874574
πΉ Severity: No Rating | π° 1,000 USD
πΉ Reported To: Shopify
πΉ Reported By: #francisbeaudoin
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 7:45pm (UTC)
Staff member with no permission can delete POS staff from account settings
π https://hackerone.com/reports/860348
πΉ Severity: Low | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #kunal94
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 7:56pm (UTC)
π https://hackerone.com/reports/860348
πΉ Severity: Low | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #kunal94
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 7:56pm (UTC)
XSS within Shopify Email App - Admin
π https://hackerone.com/reports/869831
πΉ Severity: No Rating | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #francisbeaudoin
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 7:56pm (UTC)
π https://hackerone.com/reports/869831
πΉ Severity: No Rating | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #francisbeaudoin
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 7:56pm (UTC)
[h1-2006 2020] Bounty payments are done !
π https://hackerone.com/reports/895824
πΉ Severity: Critical
πΉ Reported To: h1-ctf
πΉ Reported By: #louzogh
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 9:09pm (UTC)
π https://hackerone.com/reports/895824
πΉ Severity: Critical
πΉ Reported To: h1-ctf
πΉ Reported By: #louzogh
πΉ State: π’ Resolved
πΉ Disclosed: September 14, 2020, 9:09pm (UTC)
Adding everyone to the repo due to the lack of rate limit
π https://hackerone.com/reports/978768
πΉ Severity: High
πΉ Reported To: GitLab
πΉ Reported By: #sevilboylum
πΉ State: π΄ N/A
πΉ Disclosed: September 14, 2020, 11:28pm (UTC)
π https://hackerone.com/reports/978768
πΉ Severity: High
πΉ Reported To: GitLab
πΉ Reported By: #sevilboylum
πΉ State: π΄ N/A
πΉ Disclosed: September 14, 2020, 11:28pm (UTC)
staff can able to extend shopify trial period without admin permission
π https://hackerone.com/reports/947728
πΉ Severity: Low | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #risinghunter
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 2:15am (UTC)
π https://hackerone.com/reports/947728
πΉ Severity: Low | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #risinghunter
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 2:15am (UTC)
A staff without export customers permissions can still export customers CSV file
π https://hackerone.com/reports/860197
πΉ Severity: No Rating | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #ryat
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 4:42am (UTC)
π https://hackerone.com/reports/860197
πΉ Severity: No Rating | π° 500 USD
πΉ Reported To: Shopify
πΉ Reported By: #ryat
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 4:42am (UTC)
Email Confirmation Bypass in your-store.myshopify.com which leads to privilege escalation
π https://hackerone.com/reports/910300
πΉ Severity: Critical | π° 22,500 USD
πΉ Reported To: Shopify
πΉ Reported By: #say_ch33se
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 6:47am (UTC)
π https://hackerone.com/reports/910300
πΉ Severity: Critical | π° 22,500 USD
πΉ Reported To: Shopify
πΉ Reported By: #say_ch33se
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 6:47am (UTC)
CircleCI token in github repo allows for access to sensitive build information
π https://hackerone.com/reports/858915
πΉ Severity: No Rating | π° 1,500 USD
πΉ Reported To: Shopify
πΉ Reported By: #dwimmerlaik
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 9:30am (UTC)
π https://hackerone.com/reports/858915
πΉ Severity: No Rating | π° 1,500 USD
πΉ Reported To: Shopify
πΉ Reported By: #dwimmerlaik
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 9:30am (UTC)
[icq.im] Reflected XSS via chat invite link
π https://hackerone.com/reports/796897
πΉ Severity: Low | π° 250 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #romesful
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 12:25pm (UTC)
π https://hackerone.com/reports/796897
πΉ Severity: Low | π° 250 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #romesful
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 12:25pm (UTC)
Private files exposed to other apps
π https://hackerone.com/reports/838587
πΉ Severity: High | π° 1,000 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #kanytu
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 1:14pm (UTC)
π https://hackerone.com/reports/838587
πΉ Severity: High | π° 1,000 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #kanytu
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 1:14pm (UTC)
Database read through provider misconfiguration
π https://hackerone.com/reports/882475
πΉ Severity: Medium | π° 1,000 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #kanytu
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 1:20pm (UTC)
π https://hackerone.com/reports/882475
πΉ Severity: Medium | π° 1,000 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #kanytu
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 1:20pm (UTC)
IDOR in tracking driver logs at city-mobil.ru
π https://hackerone.com/reports/847876
πΉ Severity: Low | π° 150 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #r0hack
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 1:59pm (UTC)
π https://hackerone.com/reports/847876
πΉ Severity: Low | π° 150 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #r0hack
πΉ State: π’ Resolved
πΉ Disclosed: September 15, 2020, 1:59pm (UTC)