Hackerone Reports
222 subscribers
726 links
Last Check 2026-09-15 23:45:01
Download Telegram
🎯 New Report #2800091: Non-Production API Endpoints for the bedrock-agent Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2024-10-23
Disclosed: 2025-05-28 00:39:38
📝 Summary: The non-production API endpoints for the bedrock-agent service failed to log to CloudTrail, resulting in silent permission enumeration. A total of 26 non-production endpoints were found that could be used with standard IAM credentials without generating CloudTrail logs. This vulnerability was considered a security issue by AWS, as it allowed for invisible enumeration of permissions.
@hackeronereports
🎯 New Report #2951803: Non-Production API Endpoints for the bedrock Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-01-21
Disclosed: 2025-05-28 00:38:11
📝 Summary: The bedrock service was found to have 5 non-production API endpoints that could be used with standard IAM credentials to enumerate permissions without logging to CloudTrail. The impacted endpoints allowed the invocation of bedrock:ListImportedModels and bedrock:ListModelImportJobs actions. This vulnerability was reported to AWS, who considered it a security issue.
@hackeronereports
🎯 New Report #3021618: Non-Production API Endpoint for the EventBridge Service Fails to Log to CloudTrail Resulting in Silent Permission Enumeration
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-03-03
Disclosed: 2025-05-28 00:35:53
📝 Summary: The non-production API endpoint for the EventBridge service was found to fail to log to CloudTrail, resulting in silent permission enumeration. This vulnerability was reported to AWS, as it allowed for the enumeration of permissions of compromised credentials without generating CloudTrail logs, which could be used by adversaries to assess the access they have gained.
@hackeronereports
🎯 New Report #3029552: Non-Production API Endpoints for the Global Accelerator Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-03-10
Disclosed: 2025-05-28 00:34:30
📝 Summary: The researchers discovered that there are 8 non-production endpoints for the Global Accelerator service which can be used with standard IAM credentials and do not log to CloudTrail. This allows for silent permission enumeration, where an adversary can determine the permissions of compromised credentials without generating any logs.
@hackeronereports
🎯 New Report #3042588: Non-Production API Endpoints for the Health Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-03-17
Disclosed: 2025-05-28 00:32:46
📝 Summary: The AWS Health service was found to have 11 non-production API endpoints that could be accessed using standard IAM credentials without logging to CloudTrail. This allowed for silent permission enumeration, where an adversary could test the capabilities of compromised credentials without generating auditable CloudTrail logs.
@hackeronereports
🎯 New Report #3072841: Amazon Pinpoint SMS and Voice, version 2 Service Reporting "AWS Internal" for CloudTrail Events Generated from FIPS Endpoints
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-04-02
Disclosed: 2025-05-28 00:30:25
📝 Summary: The Amazon Pinpoint SMS and Voice, version 2 service was found to incorrectly report the user-agent and network information as "AWS Internal" for five specific API endpoints that are FIPS endpoints. This issue was discovered to be similar to a previous bug reported for the Comprehend Medical and Kendra services, suggesting a potential wider issue across a small number of services. As a result of this vulnerability, an adversary could have performed API calls using these endpoints and evaded the logging of their IP address and operating system information.
@hackeronereports
🎯 New Report #3044471: Amazon Kendra Intelligent Ranking Service Reporting "AWS Internal" for CloudTrail Events Generated from FIPS Endpoints
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-03-18
Disclosed: 2025-05-28 00:24:53
📝 Summary: The AWS Kendra Intelligent Ranking service was found to incorrectly report the user-agent and network information as "AWS Internal" for four API endpoints that are FIPS endpoints. This issue can lead to the obscuring of request information that may be used to track down an adversary.
@hackeronereports
🎯 New Report #3153497: CVE-2025-5025: No QUIC certificate pinning with wolfSSL
🔺Severity: Medium
👽 Reporter: kurohiro
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-19
Disclosed: 2025-05-28 06:35:50
📝 Summary: null
@hackeronereports
🎯 New Report #3150884: CVE-2025-4947: QUIC certificate check skip with wolfSSL
🔺Severity: Medium
👽 Reporter: kurohiro
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-17
Disclosed: 2025-05-28 06:35:36
📝 Summary: null
@hackeronereports
🎯 New Report #3122019: Remote Code Execution via unsafe usage of `reply.view({ raw })` in @fastify/view (EJS template engine)
🔺Severity: None
👽 Reporter: oblivionsage
💼 Team: Fastify
💵 Bounty: null
🕐 Submitted: 2025-05-01
Disclosed: 2025-05-28 16:56:06
📝 Summary: The @fastify/view plugin, when used with the EJS engine and the reply.view({ raw: <user-controlled-string> }) pattern, allowed arbitrary EJS execution. This vulnerability arose from the fact that Fastify trusted the raw template string without sanitization or restrictions when passed directly to EJS's compile() method, leading to Remote Code Execution.
@hackeronereports
🎯 New Report #3153497: CVE-2025-5025: No QUIC certificate pinning with wolfSSL
🔺Severity: Medium
👽 Reporter: kurohiro
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-19
Disclosed: 2025-05-28 06:35:50
📝 Summary: null
@hackeronereports
🎯 New Report #3150884: CVE-2025-4947: QUIC certificate check skip with wolfSSL
🔺Severity: Medium
👽 Reporter: kurohiro
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-17
Disclosed: 2025-05-28 06:35:36
📝 Summary: null
@hackeronereports
🎯 New Report #2800091: Non-Production API Endpoints for the bedrock-agent Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2024-10-23
Disclosed: 2025-05-28 00:39:38
📝 Summary: The non-production API endpoints for the bedrock-agent service failed to log to CloudTrail, resulting in silent permission enumeration. A total of 26 non-production endpoints were found that could be used with standard IAM credentials without generating CloudTrail logs. This vulnerability was considered a security issue by AWS, as it allowed for invisible enumeration of permissions.
@hackeronereports
🎯 New Report #3073507: Apache Airflow Fab Provider: Application does not invalidate session after password change via Airflow cli
🔺Severity: Low
👽 Reporter: saurabhb
💼 Team: Internet Bug Bounty
💵 Bounty: null
🕐 Submitted: 2025-04-02
Disclosed: 2025-05-29 12:43:25
📝 Summary: The Apache Airflow Fab Provider before version 1.5.2 was affected by an insufficient session expiration vulnerability. When a user's password was changed using the admin CLI, the existing user sessions were not cleared, allowing logged-in users to continue accessing the system even after the password change. This issue was addressed in version 1.5.2 of the Apache Airflow Fab Provider.
@hackeronereports
🎯 New Report #3119034: Facebook Username Takeover via Broken Link in Footer
🔺Severity: Low
👽 Reporter: vulnerability is here
💼 Team: Omise
💵 Bounty: null
🕐 Submitted: 2025-04-30
Disclosed: 2025-05-30 05:22:42
📝 Summary: The Facebook username "Opnglobal" was available for takeover due to a broken link in the footer of the target URL. The vulnerability allowed an attacker to create a fake Facebook page that could mislead users and negatively impact the organization's social media presence.
@hackeronereports
🎯 New Report #1365076: Information Disclosure of metrics fax.wavecell.com/metrics
🔺Severity: Low
👽 Reporter: kauenavarro
💼 Team: 8x8 Bounty
💵 Bounty: null
🕐 Submitted: 2021-10-10
Disclosed: 2025-05-30 06:53:23
📝 Summary: The fax.wavecell.com/metrics endpoint was found to disclose sensitive information. The information disclosure vulnerability was discovered and reported on the HackerOne platform.
@hackeronereports
🎯 New Report #2937622: Public GitHub repositories for multiple HackerOne managed triage team profiles contain private HackerOne reports information
🔺Severity: Low
👽 Reporter: w2w
💼 Team: HackerOne
💵 Bounty: 1200
🕐 Submitted: 2025-01-14
Disclosed: 2025-05-31 10:11:51
📝 Summary: Publicly available GitHub repositories for HackerOne-managed triage team profiles were found to contain private HackerOne vulnerability reports. Several repositories were identified that reproduced exploits for private bug bounty programs. The disclosed information included details such as access tokens, server URLs, and secret leaks for various organizations' tools and services.
@hackeronereports
🎯 New Report #3154983: IDOR: Account Deletion via Session Misbinding – Attacker Can Delete Victim Account
🔺Severity: High
👽 Reporter: z3phyrus
💼 Team: Mozilla
💵 Bounty: 6000
🕐 Submitted: 2025-05-20
Disclosed: 2025-06-03 08:38:03
📝 Summary: A critical vulnerability was identified in the Firefox Accounts API that allowed an authenticated attacker to permanently delete any user's account by sending a POST /v1/account/destroy request using the attacker's session, but including the victim's email and password hash in the JSON payload. The server failed to verify that the session making the request belonged to the account being deleted.
@hackeronereports
🎯 New Report #3165242: Server-Side Request Forgery (SSRF) via Game Export API
🔺Severity: Critical
👽 Reporter: oblivionsage
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-05-28
Disclosed: 2025-06-03 12:56:00
📝 Summary: The Lichess game export API was found to be vulnerable to Server-Side Request Forgery (SSRF) due to insufficient input validation of the "players" parameter. This allowed an attacker to make the Lichess server send arbitrary HTTP requests to external URLs, potentially exposing sensitive information.
@hackeronereports
🎯 New Report #3168039: CVE-2025-5399: WebSocket endless loop
🔺Severity: Low
👽 Reporter: z2
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-30
Disclosed: 2025-06-04 05:57:17
📝 Summary: The function curl ws send() in libcurl contains an infinite loop that can be triggered by a malicious server under specific circumstances. The loop is caused by a condition in the code that is not properly handled, leading to the function failing to terminate. This vulnerability was discovered in the libcurl library on commit 12d13b84fa40aa657b83d5458944dbd9b978fb7e.
@hackeronereports
🎯 New Report #1544236: returnUrl= allow attacker to redirect users to the another phising website and takeover credientials
🔺Severity: Medium
👽 Reporter: basant0x01
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2022-04-19
Disclosed: 2025-06-04 13:12:48
📝 Summary: The application at https://crm.na1.insightly.com was found to be vulnerable to a redirection attack. An attacker could manipulate the "returnUrl" parameter in the login authentication process to redirect users to a malicious website, potentially enabling the takeover of victims' accounts.
@hackeronereports