🎯 New Report #3072841: Amazon Pinpoint SMS and Voice, version 2 Service Reporting "AWS Internal" for CloudTrail Events Generated from FIPS Endpoints
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-04-02
⏰ Disclosed: 2025-05-28 00:30:25
📝 Summary: The Amazon Pinpoint SMS and Voice, version 2 service was found to incorrectly report the user-agent and network information as "AWS Internal" for five specific API endpoints that are FIPS endpoints. This issue was discovered to be similar to a previous bug reported for the Comprehend Medical and Kendra services, suggesting a potential wider issue across a small number of services. As a result of this vulnerability, an adversary could have performed API calls using these endpoints and evaded the logging of their IP address and operating system information.
@hackeronereports
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-04-02
⏰ Disclosed: 2025-05-28 00:30:25
📝 Summary: The Amazon Pinpoint SMS and Voice, version 2 service was found to incorrectly report the user-agent and network information as "AWS Internal" for five specific API endpoints that are FIPS endpoints. This issue was discovered to be similar to a previous bug reported for the Comprehend Medical and Kendra services, suggesting a potential wider issue across a small number of services. As a result of this vulnerability, an adversary could have performed API calls using these endpoints and evaded the logging of their IP address and operating system information.
@hackeronereports
🎯 New Report #3044471: Amazon Kendra Intelligent Ranking Service Reporting "AWS Internal" for CloudTrail Events Generated from FIPS Endpoints
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-03-18
⏰ Disclosed: 2025-05-28 00:24:53
📝 Summary: The AWS Kendra Intelligent Ranking service was found to incorrectly report the user-agent and network information as "AWS Internal" for four API endpoints that are FIPS endpoints. This issue can lead to the obscuring of request information that may be used to track down an adversary.
@hackeronereports
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2025-03-18
⏰ Disclosed: 2025-05-28 00:24:53
📝 Summary: The AWS Kendra Intelligent Ranking service was found to incorrectly report the user-agent and network information as "AWS Internal" for four API endpoints that are FIPS endpoints. This issue can lead to the obscuring of request information that may be used to track down an adversary.
@hackeronereports
🎯 New Report #3153497: CVE-2025-5025: No QUIC certificate pinning with wolfSSL
🔺Severity: Medium
👽 Reporter: kurohiro
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-19
⏰ Disclosed: 2025-05-28 06:35:50
📝 Summary: null
@hackeronereports
🔺Severity: Medium
👽 Reporter: kurohiro
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-19
⏰ Disclosed: 2025-05-28 06:35:50
📝 Summary: null
@hackeronereports
🎯 New Report #3150884: CVE-2025-4947: QUIC certificate check skip with wolfSSL
🔺Severity: Medium
👽 Reporter: kurohiro
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-17
⏰ Disclosed: 2025-05-28 06:35:36
📝 Summary: null
@hackeronereports
🔺Severity: Medium
👽 Reporter: kurohiro
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-17
⏰ Disclosed: 2025-05-28 06:35:36
📝 Summary: null
@hackeronereports
🎯 New Report #3122019: Remote Code Execution via unsafe usage of `reply.view({ raw })` in @fastify/view (EJS template engine)
🔺Severity: None
👽 Reporter: oblivionsage
💼 Team: Fastify
💵 Bounty: null
🕐 Submitted: 2025-05-01
⏰ Disclosed: 2025-05-28 16:56:06
📝 Summary: The
@hackeronereports
🔺Severity: None
👽 Reporter: oblivionsage
💼 Team: Fastify
💵 Bounty: null
🕐 Submitted: 2025-05-01
⏰ Disclosed: 2025-05-28 16:56:06
📝 Summary: The
@fastify/view plugin, when used with the EJS engine and the reply.view({ raw: <user-controlled-string> }) pattern, allowed arbitrary EJS execution. This vulnerability arose from the fact that Fastify trusted the raw template string without sanitization or restrictions when passed directly to EJS's compile() method, leading to Remote Code Execution.@hackeronereports
🎯 New Report #3153497: CVE-2025-5025: No QUIC certificate pinning with wolfSSL
🔺Severity: Medium
👽 Reporter: kurohiro
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-19
⏰ Disclosed: 2025-05-28 06:35:50
📝 Summary: null
@hackeronereports
🔺Severity: Medium
👽 Reporter: kurohiro
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-19
⏰ Disclosed: 2025-05-28 06:35:50
📝 Summary: null
@hackeronereports
🎯 New Report #3150884: CVE-2025-4947: QUIC certificate check skip with wolfSSL
🔺Severity: Medium
👽 Reporter: kurohiro
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-17
⏰ Disclosed: 2025-05-28 06:35:36
📝 Summary: null
@hackeronereports
🔺Severity: Medium
👽 Reporter: kurohiro
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-17
⏰ Disclosed: 2025-05-28 06:35:36
📝 Summary: null
@hackeronereports
🎯 New Report #2800091: Non-Production API Endpoints for the bedrock-agent Service Fail to Log to CloudTrail Resulting in Silent Permission Enumeration
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2024-10-23
⏰ Disclosed: 2025-05-28 00:39:38
📝 Summary: The non-production API endpoints for the bedrock-agent service failed to log to CloudTrail, resulting in silent permission enumeration. A total of 26 non-production endpoints were found that could be used with standard IAM credentials without generating CloudTrail logs. This vulnerability was considered a security issue by AWS, as it allowed for invisible enumeration of permissions.
@hackeronereports
🔺Severity: Medium
👽 Reporter: nick frichette dd
💼 Team: AWS VDP
💵 Bounty: null
🕐 Submitted: 2024-10-23
⏰ Disclosed: 2025-05-28 00:39:38
📝 Summary: The non-production API endpoints for the bedrock-agent service failed to log to CloudTrail, resulting in silent permission enumeration. A total of 26 non-production endpoints were found that could be used with standard IAM credentials without generating CloudTrail logs. This vulnerability was considered a security issue by AWS, as it allowed for invisible enumeration of permissions.
@hackeronereports
🎯 New Report #3073507: Apache Airflow Fab Provider: Application does not invalidate session after password change via Airflow cli
🔺Severity: Low
👽 Reporter: saurabhb
💼 Team: Internet Bug Bounty
💵 Bounty: null
🕐 Submitted: 2025-04-02
⏰ Disclosed: 2025-05-29 12:43:25
📝 Summary: The Apache Airflow Fab Provider before version 1.5.2 was affected by an insufficient session expiration vulnerability. When a user's password was changed using the admin CLI, the existing user sessions were not cleared, allowing logged-in users to continue accessing the system even after the password change. This issue was addressed in version 1.5.2 of the Apache Airflow Fab Provider.
@hackeronereports
🔺Severity: Low
👽 Reporter: saurabhb
💼 Team: Internet Bug Bounty
💵 Bounty: null
🕐 Submitted: 2025-04-02
⏰ Disclosed: 2025-05-29 12:43:25
📝 Summary: The Apache Airflow Fab Provider before version 1.5.2 was affected by an insufficient session expiration vulnerability. When a user's password was changed using the admin CLI, the existing user sessions were not cleared, allowing logged-in users to continue accessing the system even after the password change. This issue was addressed in version 1.5.2 of the Apache Airflow Fab Provider.
@hackeronereports
🎯 New Report #3119034: Facebook Username Takeover via Broken Link in Footer
🔺Severity: Low
👽 Reporter: vulnerability is here
💼 Team: Omise
💵 Bounty: null
🕐 Submitted: 2025-04-30
⏰ Disclosed: 2025-05-30 05:22:42
📝 Summary: The Facebook username "Opnglobal" was available for takeover due to a broken link in the footer of the target URL. The vulnerability allowed an attacker to create a fake Facebook page that could mislead users and negatively impact the organization's social media presence.
@hackeronereports
🔺Severity: Low
👽 Reporter: vulnerability is here
💼 Team: Omise
💵 Bounty: null
🕐 Submitted: 2025-04-30
⏰ Disclosed: 2025-05-30 05:22:42
📝 Summary: The Facebook username "Opnglobal" was available for takeover due to a broken link in the footer of the target URL. The vulnerability allowed an attacker to create a fake Facebook page that could mislead users and negatively impact the organization's social media presence.
@hackeronereports
🎯 New Report #1365076: Information Disclosure of metrics fax.wavecell.com/metrics
🔺Severity: Low
👽 Reporter: kauenavarro
💼 Team: 8x8 Bounty
💵 Bounty: null
🕐 Submitted: 2021-10-10
⏰ Disclosed: 2025-05-30 06:53:23
📝 Summary: The fax.wavecell.com/metrics endpoint was found to disclose sensitive information. The information disclosure vulnerability was discovered and reported on the HackerOne platform.
@hackeronereports
🔺Severity: Low
👽 Reporter: kauenavarro
💼 Team: 8x8 Bounty
💵 Bounty: null
🕐 Submitted: 2021-10-10
⏰ Disclosed: 2025-05-30 06:53:23
📝 Summary: The fax.wavecell.com/metrics endpoint was found to disclose sensitive information. The information disclosure vulnerability was discovered and reported on the HackerOne platform.
@hackeronereports
🎯 New Report #2937622: Public GitHub repositories for multiple HackerOne managed triage team profiles contain private HackerOne reports information
🔺Severity: Low
👽 Reporter: w2w
💼 Team: HackerOne
💵 Bounty: 1200
🕐 Submitted: 2025-01-14
⏰ Disclosed: 2025-05-31 10:11:51
📝 Summary: Publicly available GitHub repositories for HackerOne-managed triage team profiles were found to contain private HackerOne vulnerability reports. Several repositories were identified that reproduced exploits for private bug bounty programs. The disclosed information included details such as access tokens, server URLs, and secret leaks for various organizations' tools and services.
@hackeronereports
🔺Severity: Low
👽 Reporter: w2w
💼 Team: HackerOne
💵 Bounty: 1200
🕐 Submitted: 2025-01-14
⏰ Disclosed: 2025-05-31 10:11:51
📝 Summary: Publicly available GitHub repositories for HackerOne-managed triage team profiles were found to contain private HackerOne vulnerability reports. Several repositories were identified that reproduced exploits for private bug bounty programs. The disclosed information included details such as access tokens, server URLs, and secret leaks for various organizations' tools and services.
@hackeronereports
🎯 New Report #3154983: IDOR: Account Deletion via Session Misbinding – Attacker Can Delete Victim Account
🔺Severity: High
👽 Reporter: z3phyrus
💼 Team: Mozilla
💵 Bounty: 6000
🕐 Submitted: 2025-05-20
⏰ Disclosed: 2025-06-03 08:38:03
📝 Summary: A critical vulnerability was identified in the Firefox Accounts API that allowed an authenticated attacker to permanently delete any user's account by sending a
@hackeronereports
🔺Severity: High
👽 Reporter: z3phyrus
💼 Team: Mozilla
💵 Bounty: 6000
🕐 Submitted: 2025-05-20
⏰ Disclosed: 2025-06-03 08:38:03
📝 Summary: A critical vulnerability was identified in the Firefox Accounts API that allowed an authenticated attacker to permanently delete any user's account by sending a
POST /v1/account/destroy request using the attacker's session, but including the victim's email and password hash in the JSON payload. The server failed to verify that the session making the request belonged to the account being deleted.@hackeronereports
🎯 New Report #3165242: Server-Side Request Forgery (SSRF) via Game Export API
🔺Severity: Critical
👽 Reporter: oblivionsage
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-05-28
⏰ Disclosed: 2025-06-03 12:56:00
📝 Summary: The Lichess game export API was found to be vulnerable to Server-Side Request Forgery (SSRF) due to insufficient input validation of the "players" parameter. This allowed an attacker to make the Lichess server send arbitrary HTTP requests to external URLs, potentially exposing sensitive information.
@hackeronereports
🔺Severity: Critical
👽 Reporter: oblivionsage
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-05-28
⏰ Disclosed: 2025-06-03 12:56:00
📝 Summary: The Lichess game export API was found to be vulnerable to Server-Side Request Forgery (SSRF) due to insufficient input validation of the "players" parameter. This allowed an attacker to make the Lichess server send arbitrary HTTP requests to external URLs, potentially exposing sensitive information.
@hackeronereports
🎯 New Report #3168039: CVE-2025-5399: WebSocket endless loop
🔺Severity: Low
👽 Reporter: z2
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-30
⏰ Disclosed: 2025-06-04 05:57:17
📝 Summary: The function
@hackeronereports
🔺Severity: Low
👽 Reporter: z2
💼 Team: curl
💵 Bounty: null
🕐 Submitted: 2025-05-30
⏰ Disclosed: 2025-06-04 05:57:17
📝 Summary: The function
curl ws send() in libcurl contains an infinite loop that can be triggered by a malicious server under specific circumstances. The loop is caused by a condition in the code that is not properly handled, leading to the function failing to terminate. This vulnerability was discovered in the libcurl library on commit 12d13b84fa40aa657b83d5458944dbd9b978fb7e.@hackeronereports
🎯 New Report #1544236: returnUrl= allow attacker to redirect users to the another phising website and takeover credientials
🔺Severity: Medium
👽 Reporter: basant0x01
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2022-04-19
⏰ Disclosed: 2025-06-04 13:12:48
📝 Summary: The application at https://crm.na1.insightly.com was found to be vulnerable to a redirection attack. An attacker could manipulate the "returnUrl" parameter in the login authentication process to redirect users to a malicious website, potentially enabling the takeover of victims' accounts.
@hackeronereports
🔺Severity: Medium
👽 Reporter: basant0x01
💼 Team: Insightly
💵 Bounty: null
🕐 Submitted: 2022-04-19
⏰ Disclosed: 2025-06-04 13:12:48
📝 Summary: The application at https://crm.na1.insightly.com was found to be vulnerable to a redirection attack. An attacker could manipulate the "returnUrl" parameter in the login authentication process to redirect users to a malicious website, potentially enabling the takeover of victims' accounts.
@hackeronereports
🎯 New Report #1695604: DoS Vulnerability via Cache Poisoning on cdn.shopify.com and shopify-assets.shopifycdn.com
🔺Severity: Medium
👽 Reporter: bassem sadaqah
💼 Team: Shopify
💵 Bounty: 3800
🕐 Submitted: 2022-09-08
⏰ Disclosed: 2025-06-04 19:07:38
📝 Summary: There was a web cache poisoning vulnerability on Shopify's CDN domains that allowed an attacker to block access to any file hosted on the website. The vulnerability existed because the cache server treated backslashes and forward slashes as equivalent, while the origin server returned 404 errors for paths with backslashes. This discrepancy was exploited to cache 404 error pages for legitimate requests, causing a Denial of Service condition.
@hackeronereports
🔺Severity: Medium
👽 Reporter: bassem sadaqah
💼 Team: Shopify
💵 Bounty: 3800
🕐 Submitted: 2022-09-08
⏰ Disclosed: 2025-06-04 19:07:38
📝 Summary: There was a web cache poisoning vulnerability on Shopify's CDN domains that allowed an attacker to block access to any file hosted on the website. The vulnerability existed because the cache server treated backslashes and forward slashes as equivalent, while the origin server returned 404 errors for paths with backslashes. This discrepancy was exploited to cache 404 error pages for legitimate requests, causing a Denial of Service condition.
@hackeronereports
🎯 New Report #3081691: 1 Click Account Takeover via Auth Token Theft on marketing.hostinger.com
🔺Severity: High
👽 Reporter: aziz0x48
💼 Team: hostinger
💵 Bounty: null
🕐 Submitted: 2025-04-07
⏰ Disclosed: 2025-06-06 12:10:25
📝 Summary: The vulnerability discovered in the marketing.hostinger.com subdomain allowed for one-click account takeover through the theft of authentication tokens. An attacker could exploit the whitelisted redirect functionality of the subdomain to steal a victim's authentication token, which could then be used to gain full access to the victim's Hostinger account.
@hackeronereports
🔺Severity: High
👽 Reporter: aziz0x48
💼 Team: hostinger
💵 Bounty: null
🕐 Submitted: 2025-04-07
⏰ Disclosed: 2025-06-06 12:10:25
📝 Summary: The vulnerability discovered in the marketing.hostinger.com subdomain allowed for one-click account takeover through the theft of authentication tokens. An attacker could exploit the whitelisted redirect functionality of the subdomain to steal a victim's authentication token, which could then be used to gain full access to the victim's Hostinger account.
@hackeronereports
❤2
🎯 New Report #3175928: ImageId Format Injection in Image Upload Endpoint
🔺Severity: Medium
👽 Reporter: oblivionsage
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-03
⏰ Disclosed: 2025-06-06 17:43:33
📝 Summary: The image upload endpoint in the Lichess application did not properly validate the 'rel' parameter, allowing an attacker to inject special characters that broke the expected format of the generated ImageId. This could have led to parsing issues in other parts of the application that relied on the standard ImageId format.
@hackeronereports
🔺Severity: Medium
👽 Reporter: oblivionsage
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-03
⏰ Disclosed: 2025-06-06 17:43:33
📝 Summary: The image upload endpoint in the Lichess application did not properly validate the 'rel' parameter, allowing an attacker to inject special characters that broke the expected format of the generated ImageId. This could have led to parsing issues in other parts of the application that relied on the standard ImageId format.
@hackeronereports
🎯 New Report #2633771: IDOR Vulnerability at AddTagToAssets operation name
🔺Severity: Medium
👽 Reporter: root geek280
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2024-07-31
⏰ Disclosed: 2025-06-08 16:28:23
📝 Summary: The IDOR vulnerability was discovered in the AddTagToAssets operation name of a GraphQL endpoint. The vulnerability allowed an attacker to obtain the IDs of custom tags created by a victim by decoding the base64-encoded tagId parameter in the request. This revealed the format and pattern of the tag IDs, enabling the attacker to perform a brute-force attack to disclose the victim's custom tags without any interaction with the victim.
@hackeronereports
🔺Severity: Medium
👽 Reporter: root geek280
💼 Team: HackerOne
💵 Bounty: null
🕐 Submitted: 2024-07-31
⏰ Disclosed: 2025-06-08 16:28:23
📝 Summary: The IDOR vulnerability was discovered in the AddTagToAssets operation name of a GraphQL endpoint. The vulnerability allowed an attacker to obtain the IDs of custom tags created by a victim by decoding the base64-encoded tagId parameter in the request. This revealed the format and pattern of the tag IDs, enabling the attacker to perform a brute-force attack to disclose the victim's custom tags without any interaction with the victim.
@hackeronereports
🎯 New Report #3181066: Path Traversal Vulnerability in Lila Project
🔺Severity: High
👽 Reporter: immm
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-06
⏰ Disclosed: 2025-06-09 11:30:57
📝 Summary: A path traversal vulnerability was discovered in the Lila project that allowed an attacker to access arbitrary files on the server by manipulating user-supplied input to traverse outside the intended directory structure.
@hackeronereports
🔺Severity: High
👽 Reporter: immm
💼 Team: Lichess
💵 Bounty: null
🕐 Submitted: 2025-06-06
⏰ Disclosed: 2025-06-09 11:30:57
📝 Summary: A path traversal vulnerability was discovered in the Lila project that allowed an attacker to access arbitrary files on the server by manipulating user-supplied input to traverse outside the intended directory structure.
@hackeronereports