Take over subdomains of r2.dev using R2 custom domains
π https://hackerone.com/reports/1700276
πΉ Severity: Medium | π° 1,125 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #albertspedersen
πΉ State: π’ Resolved
πΉ Disclosed: September 28, 2022, 12:49pm (UTC)
π https://hackerone.com/reports/1700276
πΉ Severity: Medium | π° 1,125 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #albertspedersen
πΉ State: π’ Resolved
πΉ Disclosed: September 28, 2022, 12:49pm (UTC)
CSV export/import functionality allows administrators to modify member and message content of a workspace
π https://hackerone.com/reports/1661310
πΉ Severity: No Rating | π° 250 USD
πΉ Reported To: Slack
πΉ Reported By: #security_warrior
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 28, 2022, 8:30pm (UTC)
π https://hackerone.com/reports/1661310
πΉ Severity: No Rating | π° 250 USD
πΉ Reported To: Slack
πΉ Reported By: #security_warrior
πΉ State: βͺοΈ Informative
πΉ Disclosed: September 28, 2022, 8:30pm (UTC)
XSS in Widget Review Form Preview in settings
π https://hackerone.com/reports/1595905
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: Judge.me
πΉ Reported By: #penguinshelp
πΉ State: π’ Resolved
πΉ Disclosed: September 29, 2022, 8:35am (UTC)
π https://hackerone.com/reports/1595905
πΉ Severity: Medium | π° 500 USD
πΉ Reported To: Judge.me
πΉ Reported By: #penguinshelp
πΉ State: π’ Resolved
πΉ Disclosed: September 29, 2022, 8:35am (UTC)
no rate limit in forgot password session
π https://hackerone.com/reports/1714970
πΉ Severity: Medium
πΉ Reported To: Yelp
πΉ Reported By: #irfadps
πΉ State: π΄ N/A
πΉ Disclosed: September 29, 2022, 6:17pm (UTC)
π https://hackerone.com/reports/1714970
πΉ Severity: Medium
πΉ Reported To: Yelp
πΉ Reported By: #irfadps
πΉ State: π΄ N/A
πΉ Disclosed: September 29, 2022, 6:17pm (UTC)
Open Redirect
π https://hackerone.com/reports/1581258
πΉ Severity: Low | π° 258 USD
πΉ Reported To: Flickr
πΉ Reported By: #stevejubs
πΉ State: π’ Resolved
πΉ Disclosed: September 29, 2022, 10:51pm (UTC)
π https://hackerone.com/reports/1581258
πΉ Severity: Low | π° 258 USD
πΉ Reported To: Flickr
πΉ Reported By: #stevejubs
πΉ State: π’ Resolved
πΉ Disclosed: September 29, 2022, 10:51pm (UTC)
Password Policy Restriction Bypass
π https://hackerone.com/reports/1675730
πΉ Severity: Low | π° 250 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #lohigowda
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 8:50am (UTC)
π https://hackerone.com/reports/1675730
πΉ Severity: Low | π° 250 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #lohigowda
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 8:50am (UTC)
Lack of Packet Sanitation in Goflow Results in Multiple DoS Attack Vectors and Bugs
π https://hackerone.com/reports/1636320
πΉ Severity: High | π° 500 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #path_network
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 11:15am (UTC)
π https://hackerone.com/reports/1636320
πΉ Severity: High | π° 500 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #path_network
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 11:15am (UTC)
Unrestricted File Upload on reddit.secure.force.com
π https://hackerone.com/reports/1606957
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Reddit
πΉ Reported By: #heckintosh
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 2:56pm (UTC)
π https://hackerone.com/reports/1606957
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Reddit
πΉ Reported By: #heckintosh
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 2:56pm (UTC)
IDOR allows an attacker to modify the links of any user
π https://hackerone.com/reports/1661113
πΉ Severity: High | π° 5,000 USD
πΉ Reported To: Reddit
πΉ Reported By: #criptex
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 3:09pm (UTC)
π https://hackerone.com/reports/1661113
πΉ Severity: High | π° 5,000 USD
πΉ Reported To: Reddit
πΉ Reported By: #criptex
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 3:09pm (UTC)
Open Redirect on www.redditinc.com via `failed` query param bypass after fixed bug #1257753
π https://hackerone.com/reports/1285081
πΉ Severity: Medium | π° 200 USD
πΉ Reported To: Reddit
πΉ Reported By: #lu3ky-13
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 3:11pm (UTC)
π https://hackerone.com/reports/1285081
πΉ Severity: Medium | π° 200 USD
πΉ Reported To: Reddit
πΉ Reported By: #lu3ky-13
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 3:11pm (UTC)
Bypassing authorization of linked Instagram account
π https://hackerone.com/reports/1199965
πΉ Severity: Low | π° 170 USD
πΉ Reported To: TikTok
πΉ Reported By: #ckerha
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 9:30pm (UTC)
π https://hackerone.com/reports/1199965
πΉ Severity: Low | π° 170 USD
πΉ Reported To: TikTok
πΉ Reported By: #ckerha
πΉ State: π’ Resolved
πΉ Disclosed: September 30, 2022, 9:30pm (UTC)
π1
Generated passwords are not fully validated by HIBPValidator
π https://hackerone.com/reports/1606961
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Nextcloud
πΉ Reported By: #bjoernv
πΉ State: π’ Resolved
πΉ Disclosed: October 1, 2022, 4:50am (UTC)
π https://hackerone.com/reports/1606961
πΉ Severity: Low | π° 100 USD
πΉ Reported To: Nextcloud
πΉ Reported By: #bjoernv
πΉ State: π’ Resolved
πΉ Disclosed: October 1, 2022, 4:50am (UTC)
π1
jira discloser information
π https://hackerone.com/reports/994612
πΉ Severity: Low
πΉ Reported To: Informatica
πΉ Reported By: #isumitpatel
πΉ State: π’ Resolved
πΉ Disclosed: October 3, 2022, 1:03pm (UTC)
π https://hackerone.com/reports/994612
πΉ Severity: Low
πΉ Reported To: Informatica
πΉ Reported By: #isumitpatel
πΉ State: π’ Resolved
πΉ Disclosed: October 3, 2022, 1:03pm (UTC)
Reddit talk promotion offers don't expire, allowing users to accept them after being demoted
π https://hackerone.com/reports/1656380
πΉ Severity: Medium | π° 1,000 USD
πΉ Reported To: Reddit
πΉ Reported By: #ahacker1
πΉ State: π’ Resolved
πΉ Disclosed: October 3, 2022, 3:25pm (UTC)
π https://hackerone.com/reports/1656380
πΉ Severity: Medium | π° 1,000 USD
πΉ Reported To: Reddit
πΉ Reported By: #ahacker1
πΉ State: π’ Resolved
πΉ Disclosed: October 3, 2022, 3:25pm (UTC)
Bypass two-factor authentication
π https://hackerone.com/reports/1664974
πΉ Severity: Low | π° 250 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #ydvanjali
πΉ State: π’ Resolved
πΉ Disclosed: October 4, 2022, 12:03pm (UTC)
π https://hackerone.com/reports/1664974
πΉ Severity: Low | π° 250 USD
πΉ Reported To: Cloudflare Public Bug Bounty
πΉ Reported By: #ydvanjali
πΉ State: π’ Resolved
πΉ Disclosed: October 4, 2022, 12:03pm (UTC)
[CPP]: Add query for CWE-297: Improper Validation of Certificate with Host Mismatch
π https://hackerone.com/reports/1710575
πΉ Severity: Medium | π° 1,800 USD
πΉ Reported To: GitHub Security Lab
πΉ Reported By: #ihsinme
πΉ State: π’ Resolved
πΉ Disclosed: October 5, 2022, 5:50pm (UTC)
π https://hackerone.com/reports/1710575
πΉ Severity: Medium | π° 1,800 USD
πΉ Reported To: GitHub Security Lab
πΉ Reported By: #ihsinme
πΉ State: π’ Resolved
πΉ Disclosed: October 5, 2022, 5:50pm (UTC)
[Java]: CWE-625 - Query to detect regex dot bypass
π https://hackerone.com/reports/1690045
πΉ Severity: Low | π° 1,000 USD
πΉ Reported To: GitHub Security Lab
πΉ Reported By: #luchua
πΉ State: π’ Resolved
πΉ Disclosed: October 5, 2022, 5:50pm (UTC)
π https://hackerone.com/reports/1690045
πΉ Severity: Low | π° 1,000 USD
πΉ Reported To: GitHub Security Lab
πΉ Reported By: #luchua
πΉ State: π’ Resolved
πΉ Disclosed: October 5, 2022, 5:50pm (UTC)
[JAVA]: Partial Path Traversal
π https://hackerone.com/reports/1678405
πΉ Severity: Medium | π° 1,800 USD
πΉ Reported To: GitHub Security Lab
πΉ Reported By: #smehta23
πΉ State: π’ Resolved
πΉ Disclosed: October 5, 2022, 5:51pm (UTC)
π https://hackerone.com/reports/1678405
πΉ Severity: Medium | π° 1,800 USD
πΉ Reported To: GitHub Security Lab
πΉ Reported By: #smehta23
πΉ State: π’ Resolved
πΉ Disclosed: October 5, 2022, 5:51pm (UTC)
PYTHON: CWE-079 - Add query for email injection
π https://hackerone.com/reports/1602237
πΉ Severity: High | π° 4,500 USD
πΉ Reported To: GitHub Security Lab
πΉ Reported By: #jorgectf
πΉ State: π’ Resolved
πΉ Disclosed: October 5, 2022, 5:52pm (UTC)
π https://hackerone.com/reports/1602237
πΉ Severity: High | π° 4,500 USD
πΉ Reported To: GitHub Security Lab
πΉ Reported By: #jorgectf
πΉ State: π’ Resolved
πΉ Disclosed: October 5, 2022, 5:52pm (UTC)
IDOR - Delete technical skill assessment result & Gained Badges result of any user
π https://hackerone.com/reports/1592587
πΉ Severity: Medium | π° 1,000 USD
πΉ Reported To: LinkedIn
πΉ Reported By: #sachin_kumar_
πΉ State: π’ Resolved
πΉ Disclosed: October 5, 2022, 7:29pm (UTC)
π https://hackerone.com/reports/1592587
πΉ Severity: Medium | π° 1,000 USD
πΉ Reported To: LinkedIn
πΉ Reported By: #sachin_kumar_
πΉ State: π’ Resolved
πΉ Disclosed: October 5, 2022, 7:29pm (UTC)
No rate limit on subscribe form
π https://hackerone.com/reports/1708824
πΉ Severity: Medium
πΉ Reported To: Yelp
πΉ Reported By: #happykira0x1
πΉ State: βͺοΈ Informative
πΉ Disclosed: October 5, 2022, 8:55pm (UTC)
π https://hackerone.com/reports/1708824
πΉ Severity: Medium
πΉ Reported To: Yelp
πΉ Reported By: #happykira0x1
πΉ State: βͺοΈ Informative
πΉ Disclosed: October 5, 2022, 8:55pm (UTC)