Local file disclosure through SSRF at next.nutanix.com
π https://hackerone.com/reports/471520
πΉ Severity: High
πΉ Reported To: Nutanix
πΉ Reported By: #tosun
πΉ State: π’ Resolved
πΉ Disclosed: April 25, 2022, 10:27pm (UTC)
π https://hackerone.com/reports/471520
πΉ Severity: High
πΉ Reported To: Nutanix
πΉ Reported By: #tosun
πΉ State: π’ Resolved
πΉ Disclosed: April 25, 2022, 10:27pm (UTC)
RCE via exposed JMX server on jabber.37signals.com/jabber.basecamp.com
π https://hackerone.com/reports/1456063
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Basecamp
πΉ Reported By: #ian
πΉ State: π’ Resolved
πΉ Disclosed: April 26, 2022, 7:01am (UTC)
π https://hackerone.com/reports/1456063
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Basecamp
πΉ Reported By: #ian
πΉ State: π’ Resolved
πΉ Disclosed: April 26, 2022, 7:01am (UTC)
Stored XSS in "product type" field executed via product filters
π https://hackerone.com/reports/1404770
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: Judge.me
πΉ Reported By: #glister
πΉ State: π’ Resolved
πΉ Disclosed: April 26, 2022, 4:11pm (UTC)
π https://hackerone.com/reports/1404770
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: Judge.me
πΉ Reported By: #glister
πΉ State: π’ Resolved
πΉ Disclosed: April 26, 2022, 4:11pm (UTC)
SQL Injection on https://soa-accp.glbx.tva.gov/ via "/api/" path - VI-21-015
π https://hackerone.com/reports/1125752
πΉ Severity: Critical
πΉ Reported To: Tennessee Valley Authority
πΉ Reported By: #yassinek3ch
πΉ State: π’ Resolved
πΉ Disclosed: April 26, 2022, 7:33pm (UTC)
π https://hackerone.com/reports/1125752
πΉ Severity: Critical
πΉ Reported To: Tennessee Valley Authority
πΉ Reported By: #yassinek3ch
πΉ State: π’ Resolved
πΉ Disclosed: April 26, 2022, 7:33pm (UTC)
CVE-2022-27774: Credential leak on redirect
π https://hackerone.com/reports/1543773
πΉ Severity: High
πΉ Reported To: curl
πΉ Reported By: #nyymi
πΉ State: π’ Resolved
πΉ Disclosed: April 27, 2022, 9:58am (UTC)
π https://hackerone.com/reports/1543773
πΉ Severity: High
πΉ Reported To: curl
πΉ Reported By: #nyymi
πΉ State: π’ Resolved
πΉ Disclosed: April 27, 2022, 9:58am (UTC)
CVE-2022-27775: Bad local IPv6 connection reuse
π https://hackerone.com/reports/1546268
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: #nyymi
πΉ State: π’ Resolved
πΉ Disclosed: April 27, 2022, 9:58am (UTC)
π https://hackerone.com/reports/1546268
πΉ Severity: Low
πΉ Reported To: curl
πΉ Reported By: #nyymi
πΉ State: π’ Resolved
πΉ Disclosed: April 27, 2022, 9:58am (UTC)
CVE-2022-27776: Auth/cookie leak on redirect
π https://hackerone.com/reports/1547048
πΉ Severity: Medium
πΉ Reported To: curl
πΉ Reported By: #nyymi
πΉ State: π’ Resolved
πΉ Disclosed: April 27, 2022, 9:58am (UTC)
π https://hackerone.com/reports/1547048
πΉ Severity: Medium
πΉ Reported To: curl
πΉ Reported By: #nyymi
πΉ State: π’ Resolved
πΉ Disclosed: April 27, 2022, 9:58am (UTC)
Container escape on public GitLab CI runners
π https://hackerone.com/reports/1442118
πΉ Severity: High
πΉ Reported To: GitLab
πΉ Reported By: #ec0
πΉ State: βͺοΈ Informative
πΉ Disclosed: April 27, 2022, 11:12am (UTC)
π https://hackerone.com/reports/1442118
πΉ Severity: High
πΉ Reported To: GitLab
πΉ Reported By: #ec0
πΉ State: βͺοΈ Informative
πΉ Disclosed: April 27, 2022, 11:12am (UTC)
subdomain takeover (abandoned Zendesk β.easycontactnow.com)
π https://hackerone.com/reports/1486670
πΉ Severity: Medium
πΉ Reported To: 8x8
πΉ Reported By: #bx_1
πΉ State: π’ Resolved
πΉ Disclosed: April 28, 2022, 5:59am (UTC)
π https://hackerone.com/reports/1486670
πΉ Severity: Medium
πΉ Reported To: 8x8
πΉ Reported By: #bx_1
πΉ State: π’ Resolved
πΉ Disclosed: April 28, 2022, 5:59am (UTC)
CVE-2022-27774: Credential leak on redirect
π https://hackerone.com/reports/1551586
πΉ Severity: Medium | π° 2,400 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #nyymi
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 6:32am (UTC)
π https://hackerone.com/reports/1551586
πΉ Severity: Medium | π° 2,400 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #nyymi
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 6:32am (UTC)
CVE-2022-27775: Bad local IPv6 connection reuse
π https://hackerone.com/reports/1551588
πΉ Severity: Low | π° 480 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #nyymi
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 6:32am (UTC)
π https://hackerone.com/reports/1551588
πΉ Severity: Low | π° 480 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #nyymi
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 6:32am (UTC)
CVE-2022-27776: Auth/cookie leak on redirect
π https://hackerone.com/reports/1551591
πΉ Severity: Low | π° 480 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #nyymi
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 6:32am (UTC)
π https://hackerone.com/reports/1551591
πΉ Severity: Low | π° 480 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #nyymi
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 6:32am (UTC)
DoS via large console messages
π https://hackerone.com/reports/1243724
πΉ Severity: Low | π° 150 USD
πΉ Reported To: Mattermost
πΉ Reported By: #thesecuritydev
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 7:11am (UTC)
π https://hackerone.com/reports/1243724
πΉ Severity: Low | π° 150 USD
πΉ Reported To: Mattermost
πΉ Reported By: #thesecuritydev
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 7:11am (UTC)
CVE-2022-22576: OAUTH2 bearer bypass in connection re-use
π https://hackerone.com/reports/1526328
πΉ Severity: Medium
πΉ Reported To: curl
πΉ Reported By: #monnerat
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 11:27am (UTC)
π https://hackerone.com/reports/1526328
πΉ Severity: Medium
πΉ Reported To: curl
πΉ Reported By: #monnerat
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 11:27am (UTC)
OAUTH2 bearer not-checked for connection re-use
π https://hackerone.com/reports/1552110
πΉ Severity: Medium | π° 2,400 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #monnerat
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 11:34am (UTC)
π https://hackerone.com/reports/1552110
πΉ Severity: Medium | π° 2,400 USD
πΉ Reported To: Internet Bug Bounty
πΉ Reported By: #monnerat
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 11:34am (UTC)
Possibility to force an admin to install recommended applications
π https://hackerone.com/reports/1403614
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Nextcloud
πΉ Reported By: #igorpyan
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 11:50am (UTC)
π https://hackerone.com/reports/1403614
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Nextcloud
πΉ Reported By: #igorpyan
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 11:50am (UTC)
π1
SQL INJECTION in https://ββββ/ββββββββββ
π https://hackerone.com/reports/723044
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #mido0x0x
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 1:56pm (UTC)
π https://hackerone.com/reports/723044
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #mido0x0x
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 1:56pm (UTC)
Blind SQL Injection
π https://hackerone.com/reports/771215
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #mido0x0x
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 1:57pm (UTC)
π https://hackerone.com/reports/771215
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #mido0x0x
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 1:57pm (UTC)
ββββββββββ vulnerable to CVE-2022-22954
π https://hackerone.com/reports/1537543
πΉ Severity: Critical
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #null_bytes
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 1:58pm (UTC)
π https://hackerone.com/reports/1537543
πΉ Severity: Critical
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #null_bytes
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 1:58pm (UTC)
SSRF due to CVE-2021-27905 in www.ββββββββ
π https://hackerone.com/reports/1183472
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #fdeleite
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 2:00pm (UTC)
π https://hackerone.com/reports/1183472
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #fdeleite
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 2:00pm (UTC)
Sensitive data exposure via /secure/QueryComponent!Default.jspa endpoint on ββββββββ
π https://hackerone.com/reports/1278977
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #njmulsqb
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 2:03pm (UTC)
π https://hackerone.com/reports/1278977
πΉ Severity: Medium
πΉ Reported To: U.S. Dept Of Defense
πΉ Reported By: #njmulsqb
πΉ State: π’ Resolved
πΉ Disclosed: April 29, 2022, 2:03pm (UTC)