Improper input validation in projects leads to fully deny access to project resources
π https://hackerone.com/reports/1237700
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: Semrush
πΉ Reported By: #a_d_a_m
πΉ State: π’ Resolved
πΉ Disclosed: September 1, 2021, 8:11pm (UTC)
π https://hackerone.com/reports/1237700
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: Semrush
πΉ Reported By: #a_d_a_m
πΉ State: π’ Resolved
πΉ Disclosed: September 1, 2021, 8:11pm (UTC)
e-mail verification bypass through interception & modification of response status
π https://hackerone.com/reports/1181253
πΉ Severity: No Rating
πΉ Reported To: U.S. General Services Administration
πΉ Reported By: #rajeshpatil
πΉ State: π’ Resolved
πΉ Disclosed: September 2, 2021, 2:46pm (UTC)
π https://hackerone.com/reports/1181253
πΉ Severity: No Rating
πΉ Reported To: U.S. General Services Administration
πΉ Reported By: #rajeshpatil
πΉ State: π’ Resolved
πΉ Disclosed: September 2, 2021, 2:46pm (UTC)
Java: Static initialization vector
π https://hackerone.com/reports/1329260
πΉ Severity: Medium
πΉ Reported To: GitHub Security Lab
πΉ Reported By: #not_specified
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2021, 12:15am (UTC)
π https://hackerone.com/reports/1329260
πΉ Severity: Medium
πΉ Reported To: GitHub Security Lab
πΉ Reported By: #not_specified
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2021, 12:15am (UTC)
Improper Authentication - any user can login as other user with otp/logout & otp/login
π https://hackerone.com/reports/921780
πΉ Severity: Critical | π° 25,000 USD
πΉ Reported To: Snapchat
πΉ Reported By: #korniltsev
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2021, 9:12am (UTC)
π https://hackerone.com/reports/921780
πΉ Severity: Critical | π° 25,000 USD
πΉ Reported To: Snapchat
πΉ Reported By: #korniltsev
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2021, 9:12am (UTC)
Protocol Smuggling over LDAP password field
π https://hackerone.com/reports/1054282
πΉ Severity: Low | π° 50 USD
πΉ Reported To: ownCloud
πΉ Reported By: #pabl00nicarres
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2021, 1:20pm (UTC)
π https://hackerone.com/reports/1054282
πΉ Severity: Low | π° 50 USD
πΉ Reported To: ownCloud
πΉ Reported By: #pabl00nicarres
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2021, 1:20pm (UTC)
Payment method token being sent to 3rd party analytics service
π https://hackerone.com/reports/637267
πΉ Severity: High | π° 2,500 USD
πΉ Reported To: Upserve
πΉ Reported By: #ctulhu
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2021, 3:06pm (UTC)
π https://hackerone.com/reports/637267
πΉ Severity: High | π° 2,500 USD
πΉ Reported To: Upserve
πΉ Reported By: #ctulhu
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2021, 3:06pm (UTC)
Possible to invite any team member without being logged in. [ Session Management Issue ]
π https://hackerone.com/reports/1319892
πΉ Severity: Medium
πΉ Reported To: Courier
πΉ Reported By: #bugera
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2021, 7:28pm (UTC)
π https://hackerone.com/reports/1319892
πΉ Severity: Medium
πΉ Reported To: Courier
πΉ Reported By: #bugera
πΉ State: π’ Resolved
πΉ Disclosed: September 3, 2021, 7:28pm (UTC)
Google Maps API Key Leakage
π https://hackerone.com/reports/1321830
πΉ Severity: High
πΉ Reported To: Uber
πΉ Reported By: #batman9
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 3, 2021, 8:39pm (UTC)
π https://hackerone.com/reports/1321830
πΉ Severity: High
πΉ Reported To: Uber
πΉ Reported By: #batman9
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 3, 2021, 8:39pm (UTC)
No Limit on Email Subscription
π https://hackerone.com/reports/1085079
πΉ Severity: Low
πΉ Reported To: OpenMage
πΉ Reported By: #thecyberjerry
πΉ State: π’ Resolved
πΉ Disclosed: September 4, 2021, 7:05am (UTC)
π https://hackerone.com/reports/1085079
πΉ Severity: Low
πΉ Reported To: OpenMage
πΉ Reported By: #thecyberjerry
πΉ State: π’ Resolved
πΉ Disclosed: September 4, 2021, 7:05am (UTC)
XSS Stored in Cacheable response
π https://hackerone.com/reports/1011093
πΉ Severity: Medium | π° 50 USD
πΉ Reported To: Acronis
πΉ Reported By: #dj4ng0d2
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2021, 1:47am (UTC)
π https://hackerone.com/reports/1011093
πΉ Severity: Medium | π° 50 USD
πΉ Reported To: Acronis
πΉ Reported By: #dj4ng0d2
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2021, 1:47am (UTC)
ΠΠΎΠ΄ΠΌΠ΅Π½Π° ΡΠΎΡΠΎΠ³ΡΠ°ΡΠΈΠΉ Π°Π²ΡΠΎΠΌΠΎΠ±ΠΈΠ»Ρ [city-mobil.ru/taxiserv/]
π https://hackerone.com/reports/1130528
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #lobity
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2021, 10:51am (UTC)
π https://hackerone.com/reports/1130528
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #lobity
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2021, 10:51am (UTC)
informations disclosure(Email,Numbers,Agreements, admin Sessions and more ...) through a PostgreSQL database belongs to (legium-back.corp.mail.ru)
π https://hackerone.com/reports/1241637
πΉ Severity: Medium | π° 150 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #yukusawa18
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2021, 11:41am (UTC)
π https://hackerone.com/reports/1241637
πΉ Severity: Medium | π° 150 USD
πΉ Reported To: Mail.ru
πΉ Reported By: #yukusawa18
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2021, 11:41am (UTC)
Node Validation Admission does not observe all oldObject fields
π https://hackerone.com/reports/1095612
πΉ Severity: Medium | π° 1,000 USD
πΉ Reported To: Kubernetes
πΉ Reported By: #ariellima
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2021, 11:17pm (UTC)
π https://hackerone.com/reports/1095612
πΉ Severity: Medium | π° 1,000 USD
πΉ Reported To: Kubernetes
πΉ Reported By: #ariellima
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2021, 11:17pm (UTC)
Holes in EndpointSlice Validation Enable Host Network Hijack
π https://hackerone.com/reports/1145044
πΉ Severity: Low | π° 200 USD
πΉ Reported To: Kubernetes
πΉ Reported By: #howardjohn
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2021, 11:29pm (UTC)
π https://hackerone.com/reports/1145044
πΉ Severity: Low | π° 200 USD
πΉ Reported To: Kubernetes
πΉ Reported By: #howardjohn
πΉ State: π’ Resolved
πΉ Disclosed: September 5, 2021, 11:29pm (UTC)
XSS on ub.icq.net
π https://hackerone.com/reports/1064587
πΉ Severity: Low
πΉ Reported To: Mail.ru
πΉ Reported By: #nightmare_msf
πΉ State: π’ Resolved
πΉ Disclosed: September 6, 2021, 12:53pm (UTC)
π https://hackerone.com/reports/1064587
πΉ Severity: Low
πΉ Reported To: Mail.ru
πΉ Reported By: #nightmare_msf
πΉ State: π’ Resolved
πΉ Disclosed: September 6, 2021, 12:53pm (UTC)
Social Oauth Disconnect CSRF at znakcup.ru
π https://hackerone.com/reports/1074869
πΉ Severity: Medium
πΉ Reported To: Mail.ru
πΉ Reported By: #nightmare_msf
πΉ State: π’ Resolved
πΉ Disclosed: September 6, 2021, 1:28pm (UTC)
π https://hackerone.com/reports/1074869
πΉ Severity: Medium
πΉ Reported To: Mail.ru
πΉ Reported By: #nightmare_msf
πΉ State: π’ Resolved
πΉ Disclosed: September 6, 2021, 1:28pm (UTC)
Bootstrap library is vulnerable
π https://hackerone.com/reports/1198203
πΉ Severity: Low
πΉ Reported To: Sifchain
πΉ Reported By: #sathish87
πΉ State: π΄ N/A
πΉ Disclosed: September 6, 2021, 4:40pm (UTC)
π https://hackerone.com/reports/1198203
πΉ Severity: Low
πΉ Reported To: Sifchain
πΉ Reported By: #sathish87
πΉ State: π΄ N/A
πΉ Disclosed: September 6, 2021, 4:40pm (UTC)
subdomain takeover disney.samokat.ru
π https://hackerone.com/reports/1052819
πΉ Severity: Medium
πΉ Reported To: Mail.ru
πΉ Reported By: #nanwn
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2021, 9:29am (UTC)
π https://hackerone.com/reports/1052819
πΉ Severity: Medium
πΉ Reported To: Mail.ru
πΉ Reported By: #nanwn
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2021, 9:29am (UTC)
Path Traversal in dict-fs and no-check Escape Character in oauth2-jwt
π https://hackerone.com/reports/1132160
πΉ Severity: Medium | π° 982 USD
πΉ Reported To: Open-Xchange
πΉ Reported By: #northsea
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2021, 10:10am (UTC)
π https://hackerone.com/reports/1132160
πΉ Severity: Medium | π° 982 USD
πΉ Reported To: Open-Xchange
πΉ Reported By: #northsea
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2021, 10:10am (UTC)
HTML Injection @ /[restaurant]/order endpoint.
π https://hackerone.com/reports/738810
πΉ Severity: Low | π° 150 USD
πΉ Reported To: Zomato
πΉ Reported By: #mr_edwards
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2021, 11:28am (UTC)
π https://hackerone.com/reports/738810
πΉ Severity: Low | π° 150 USD
πΉ Reported To: Zomato
πΉ Reported By: #mr_edwards
πΉ State: π’ Resolved
πΉ Disclosed: September 7, 2021, 11:28am (UTC)