Bugpoint
1.05K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
DNS rebinding in --inspect (insufficient fix of CVE-2022-32212 affecting macOS devices)

πŸ‘‰ https://hackerone.com/reports/1632921

πŸ”Ή Severity: High
πŸ”Ή Reported To: Node.js
πŸ”Ή Reported By: #zeyu2001
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 28, 2022, 8:38am (UTC)
Take over subdomains of r2.dev using R2 custom domains

πŸ‘‰ https://hackerone.com/reports/1700276

πŸ”Ή Severity: Medium | πŸ’° 1,125 USD
πŸ”Ή Reported To: Cloudflare Public Bug Bounty
πŸ”Ή Reported By: #albertspedersen
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 28, 2022, 12:49pm (UTC)
CSV export/import functionality allows administrators to modify member and message content of a workspace

πŸ‘‰ https://hackerone.com/reports/1661310

πŸ”Ή Severity: No Rating | πŸ’° 250 USD
πŸ”Ή Reported To: Slack
πŸ”Ή Reported By: #security_warrior
πŸ”Ή State: βšͺ️ Informative
πŸ”Ή Disclosed: September 28, 2022, 8:30pm (UTC)
XSS in Widget Review Form Preview in settings

πŸ‘‰ https://hackerone.com/reports/1595905

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: Judge.me
πŸ”Ή Reported By: #penguinshelp
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 29, 2022, 8:35am (UTC)
no rate limit in forgot password session

πŸ‘‰ https://hackerone.com/reports/1714970

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Yelp
πŸ”Ή Reported By: #irfadps
πŸ”Ή State: πŸ”΄ N/A
πŸ”Ή Disclosed: September 29, 2022, 6:17pm (UTC)
Open Redirect

πŸ‘‰ https://hackerone.com/reports/1581258

πŸ”Ή Severity: Low | πŸ’° 258 USD
πŸ”Ή Reported To: Flickr
πŸ”Ή Reported By: #stevejubs
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 29, 2022, 10:51pm (UTC)
Password Policy Restriction Bypass

πŸ‘‰ https://hackerone.com/reports/1675730

πŸ”Ή Severity: Low | πŸ’° 250 USD
πŸ”Ή Reported To: Cloudflare Public Bug Bounty
πŸ”Ή Reported By: #lohigowda
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 30, 2022, 8:50am (UTC)
Lack of Packet Sanitation in Goflow Results in Multiple DoS Attack Vectors and Bugs

πŸ‘‰ https://hackerone.com/reports/1636320

πŸ”Ή Severity: High | πŸ’° 500 USD
πŸ”Ή Reported To: Cloudflare Public Bug Bounty
πŸ”Ή Reported By: #path_network
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 30, 2022, 11:15am (UTC)
Unrestricted File Upload on reddit.secure.force.com

πŸ‘‰ https://hackerone.com/reports/1606957

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Reddit
πŸ”Ή Reported By: #heckintosh
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 30, 2022, 2:56pm (UTC)
IDOR allows an attacker to modify the links of any user

πŸ‘‰ https://hackerone.com/reports/1661113

πŸ”Ή Severity: High | πŸ’° 5,000 USD
πŸ”Ή Reported To: Reddit
πŸ”Ή Reported By: #criptex
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 30, 2022, 3:09pm (UTC)
Open Redirect on www.redditinc.com via `failed` query param bypass after fixed bug #1257753

πŸ‘‰ https://hackerone.com/reports/1285081

πŸ”Ή Severity: Medium | πŸ’° 200 USD
πŸ”Ή Reported To: Reddit
πŸ”Ή Reported By: #lu3ky-13
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 30, 2022, 3:11pm (UTC)
Bypassing authorization of linked Instagram account

πŸ‘‰ https://hackerone.com/reports/1199965

πŸ”Ή Severity: Low | πŸ’° 170 USD
πŸ”Ή Reported To: TikTok
πŸ”Ή Reported By: #ckerha
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 30, 2022, 9:30pm (UTC)
πŸ‘1
Generated passwords are not fully validated by HIBPValidator

πŸ‘‰ https://hackerone.com/reports/1606961

πŸ”Ή Severity: Low | πŸ’° 100 USD
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #bjoernv
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 1, 2022, 4:50am (UTC)
πŸ‘1
jira discloser information

πŸ‘‰ https://hackerone.com/reports/994612

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Informatica
πŸ”Ή Reported By: #isumitpatel
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 3, 2022, 1:03pm (UTC)
Reddit talk promotion offers don't expire, allowing users to accept them after being demoted

πŸ‘‰ https://hackerone.com/reports/1656380

πŸ”Ή Severity: Medium | πŸ’° 1,000 USD
πŸ”Ή Reported To: Reddit
πŸ”Ή Reported By: #ahacker1
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 3, 2022, 3:25pm (UTC)
Bypass two-factor authentication

πŸ‘‰ https://hackerone.com/reports/1664974

πŸ”Ή Severity: Low | πŸ’° 250 USD
πŸ”Ή Reported To: Cloudflare Public Bug Bounty
πŸ”Ή Reported By: #ydvanjali
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 4, 2022, 12:03pm (UTC)
[CPP]: Add query for CWE-297: Improper Validation of Certificate with Host Mismatch

πŸ‘‰ https://hackerone.com/reports/1710575

πŸ”Ή Severity: Medium | πŸ’° 1,800 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #ihsinme
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 5, 2022, 5:50pm (UTC)
[Java]: CWE-625 - Query to detect regex dot bypass

πŸ‘‰ https://hackerone.com/reports/1690045

πŸ”Ή Severity: Low | πŸ’° 1,000 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #luchua
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 5, 2022, 5:50pm (UTC)
[JAVA]: Partial Path Traversal

πŸ‘‰ https://hackerone.com/reports/1678405

πŸ”Ή Severity: Medium | πŸ’° 1,800 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #smehta23
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 5, 2022, 5:51pm (UTC)
PYTHON: CWE-079 - Add query for email injection

πŸ‘‰ https://hackerone.com/reports/1602237

πŸ”Ή Severity: High | πŸ’° 4,500 USD
πŸ”Ή Reported To: GitHub Security Lab
πŸ”Ή Reported By: #jorgectf
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 5, 2022, 5:52pm (UTC)
IDOR - Delete technical skill assessment result & Gained Badges result of any user

πŸ‘‰ https://hackerone.com/reports/1592587

πŸ”Ή Severity: Medium | πŸ’° 1,000 USD
πŸ”Ή Reported To: LinkedIn
πŸ”Ή Reported By: #sachin_kumar_
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: October 5, 2022, 7:29pm (UTC)