All private support requests to ███████ are being disclosed at https://███████
👉 https://hackerone.com/reports/1004964
🔹 Severity: High
🔹 Reported To: U.S. Dept Of Defense
🔹 Reported By: #nagli
🔹 State: 🟢 Resolved
🔹 Disclosed: July 29, 2021, 7:53pm (UTC)
👉 https://hackerone.com/reports/1004964
🔹 Severity: High
🔹 Reported To: U.S. Dept Of Defense
🔹 Reported By: #nagli
🔹 State: 🟢 Resolved
🔹 Disclosed: July 29, 2021, 7:53pm (UTC)
CSRF when unlocking lenses leads to lenses being forcefully installed without user interaction
👉 https://hackerone.com/reports/1085336
🔹 Severity: Low | 💰 250 USD
🔹 Reported To: Snapchat
🔹 Reported By: #sdushantha
🔹 State: 🟢 Resolved
🔹 Disclosed: July 29, 2021, 10:33pm (UTC)
👉 https://hackerone.com/reports/1085336
🔹 Severity: Low | 💰 250 USD
🔹 Reported To: Snapchat
🔹 Reported By: #sdushantha
🔹 State: 🟢 Resolved
🔹 Disclosed: July 29, 2021, 10:33pm (UTC)
Publicly accessible Continuous Integration Tool
👉 https://hackerone.com/reports/313457
🔹 Severity: Critical | 💰 25,000 USD
🔹 Reported To: Snapchat
🔹 Reported By: #apfeifer27
🔹 State: 🟢 Resolved
🔹 Disclosed: July 29, 2021, 10:36pm (UTC)
👉 https://hackerone.com/reports/313457
🔹 Severity: Critical | 💰 25,000 USD
🔹 Reported To: Snapchat
🔹 Reported By: #apfeifer27
🔹 State: 🟢 Resolved
🔹 Disclosed: July 29, 2021, 10:36pm (UTC)
Stealing SSO Login Tokens (snappublisher.snapchat.com)
👉 https://hackerone.com/reports/265943
🔹 Severity: High | 💰 7,500 USD
🔹 Reported To: Snapchat
🔹 Reported By: #coolboss
🔹 State: 🟢 Resolved
🔹 Disclosed: July 29, 2021, 10:37pm (UTC)
👉 https://hackerone.com/reports/265943
🔹 Severity: High | 💰 7,500 USD
🔹 Reported To: Snapchat
🔹 Reported By: #coolboss
🔹 State: 🟢 Resolved
🔹 Disclosed: July 29, 2021, 10:37pm (UTC)
Exposed Kubernetes API - RCE/Exposed Creds
👉 https://hackerone.com/reports/455645
🔹 Severity: Critical | 💰 25,000 USD
🔹 Reported To: Snapchat
🔹 Reported By: #txt3rob
🔹 State: 🟢 Resolved
🔹 Disclosed: July 29, 2021, 10:37pm (UTC)
👉 https://hackerone.com/reports/455645
🔹 Severity: Critical | 💰 25,000 USD
🔹 Reported To: Snapchat
🔹 Reported By: #txt3rob
🔹 State: 🟢 Resolved
🔹 Disclosed: July 29, 2021, 10:37pm (UTC)
Bypassing Content-Security-Policy leads to open-redirect and iframe xss
👉 https://hackerone.com/reports/1166766
🔹 Severity: Medium
🔹 Reported To: Stripo Inc
🔹 Reported By: #jmrcsnchz
🔹 State: 🟢 Resolved
🔹 Disclosed: July 30, 2021, 5:33am (UTC)
👉 https://hackerone.com/reports/1166766
🔹 Severity: Medium
🔹 Reported To: Stripo Inc
🔹 Reported By: #jmrcsnchz
🔹 State: 🟢 Resolved
🔹 Disclosed: July 30, 2021, 5:33am (UTC)
DNS Misconfiguration (Subdomain Takeover) - █████████.8x8.com
👉 https://hackerone.com/reports/1280167
🔹 Severity: Medium
🔹 Reported To: 8x8
🔹 Reported By: #melbadry9
🔹 State: 🟢 Resolved
🔹 Disclosed: July 30, 2021, 9:57am (UTC)
👉 https://hackerone.com/reports/1280167
🔹 Severity: Medium
🔹 Reported To: 8x8
🔹 Reported By: #melbadry9
🔹 State: 🟢 Resolved
🔹 Disclosed: July 30, 2021, 9:57am (UTC)
url redirection
👉 https://hackerone.com/reports/1283200
🔹 Severity: Critical
🔹 Reported To: UPchieve
🔹 Reported By: #ben_lay
🔹 State: 🔴 N/A
🔹 Disclosed: July 30, 2021, 2:33pm (UTC)
👉 https://hackerone.com/reports/1283200
🔹 Severity: Critical
🔹 Reported To: UPchieve
🔹 Reported By: #ben_lay
🔹 State: 🔴 N/A
🔹 Disclosed: July 30, 2021, 2:33pm (UTC)
Bitmoji source code is accessible
👉 https://hackerone.com/reports/301812
🔹 Severity: Medium | 💰 1,000 USD
🔹 Reported To: Snapchat
🔹 Reported By: #rms
🔹 State: 🟢 Resolved
🔹 Disclosed: July 31, 2021, 12:20am (UTC)
👉 https://hackerone.com/reports/301812
🔹 Severity: Medium | 💰 1,000 USD
🔹 Reported To: Snapchat
🔹 Reported By: #rms
🔹 State: 🟢 Resolved
🔹 Disclosed: July 31, 2021, 12:20am (UTC)
Post-Auth Blind NoSQL Injection in the users.list API leads to Remote Code Execution
👉 https://hackerone.com/reports/1130874
🔹 Severity: High
🔹 Reported To: Rocket.Chat
🔹 Reported By: #sonarsource
🔹 State: 🟢 Resolved
🔹 Disclosed: July 31, 2021, 8:31am (UTC)
👉 https://hackerone.com/reports/1130874
🔹 Severity: High
🔹 Reported To: Rocket.Chat
🔹 Reported By: #sonarsource
🔹 State: 🟢 Resolved
🔹 Disclosed: July 31, 2021, 8:31am (UTC)
Two-factor authentication enforcement bypass
👉 https://hackerone.com/reports/1050244
🔹 Severity: High | 💰 750 USD
🔹 Reported To: Nextcloud
🔹 Reported By: #abdullah-a
🔹 State: 🟢 Resolved
🔹 Disclosed: July 31, 2021, 2:05pm (UTC)
👉 https://hackerone.com/reports/1050244
🔹 Severity: High | 💰 750 USD
🔹 Reported To: Nextcloud
🔹 Reported By: #abdullah-a
🔹 State: 🟢 Resolved
🔹 Disclosed: July 31, 2021, 2:05pm (UTC)
Vulnerable javanoscript dependency at Main domain
👉 https://hackerone.com/reports/1188643
🔹 Severity: Low
🔹 Reported To: Sifchain
🔹 Reported By: #n33dm0n3y
🔹 State: 🔴 N/A
🔹 Disclosed: August 2, 2021, 12:03am (UTC)
👉 https://hackerone.com/reports/1188643
🔹 Severity: Low
🔹 Reported To: Sifchain
🔹 Reported By: #n33dm0n3y
🔹 State: 🔴 N/A
🔹 Disclosed: August 2, 2021, 12:03am (UTC)
When uploading attachments, unencrypted file names are made available to the server
👉 https://hackerone.com/reports/1206799
🔹 Severity: No Rating
🔹 Reported To: Bitwarden
🔹 Reported By: #jjlin
🔹 State: 🟢 Resolved
🔹 Disclosed: August 2, 2021, 1:52pm (UTC)
👉 https://hackerone.com/reports/1206799
🔹 Severity: No Rating
🔹 Reported To: Bitwarden
🔹 Reported By: #jjlin
🔹 State: 🟢 Resolved
🔹 Disclosed: August 2, 2021, 1:52pm (UTC)
CSRF on /api/graphql allows executing mutations through GET requests
👉 https://hackerone.com/reports/1122408
🔹 Severity: High | 💰 3,370 USD
🔹 Reported To: GitLab
🔹 Reported By: #az3z3l
🔹 State: 🟢 Resolved
🔹 Disclosed: August 2, 2021, 7:10pm (UTC)
👉 https://hackerone.com/reports/1122408
🔹 Severity: High | 💰 3,370 USD
🔹 Reported To: GitLab
🔹 Reported By: #az3z3l
🔹 State: 🟢 Resolved
🔹 Disclosed: August 2, 2021, 7:10pm (UTC)
[Java] CWE-601: Add Spring URL Redirect ResponseEntity sink
👉 https://hackerone.com/reports/1287577
🔹 Severity: Medium | 💰 1,800 USD
🔹 Reported To: GitHub Security Lab
🔹 Reported By: #p0wn4j
🔹 State: 🟢 Resolved
🔹 Disclosed: August 2, 2021, 8:59pm (UTC)
👉 https://hackerone.com/reports/1287577
🔹 Severity: Medium | 💰 1,800 USD
🔹 Reported To: GitHub Security Lab
🔹 Reported By: #p0wn4j
🔹 State: 🟢 Resolved
🔹 Disclosed: August 2, 2021, 8:59pm (UTC)
[Python]: Add SqlAlchemy support for SQL injection query
👉 https://hackerone.com/reports/1287576
🔹 Severity: High
🔹 Reported To: GitHub Security Lab
🔹 Reported By: #not_specified
🔹 State: 🟢 Resolved
🔹 Disclosed: August 2, 2021, 9:00pm (UTC)
👉 https://hackerone.com/reports/1287576
🔹 Severity: High
🔹 Reported To: GitHub Security Lab
🔹 Reported By: #not_specified
🔹 State: 🟢 Resolved
🔹 Disclosed: August 2, 2021, 9:00pm (UTC)
[Python] CWE-287: LDAP Improper Authentication
👉 https://hackerone.com/reports/1287575
🔹 Severity: Medium | 💰 1,800 USD
🔹 Reported To: GitHub Security Lab
🔹 Reported By: #jorgectf
🔹 State: 🟢 Resolved
🔹 Disclosed: August 2, 2021, 9:00pm (UTC)
👉 https://hackerone.com/reports/1287575
🔹 Severity: Medium | 💰 1,800 USD
🔹 Reported To: GitHub Security Lab
🔹 Reported By: #jorgectf
🔹 State: 🟢 Resolved
🔹 Disclosed: August 2, 2021, 9:00pm (UTC)
[Java] CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
👉 https://hackerone.com/reports/1287574
🔹 Severity: Medium
🔹 Reported To: GitHub Security Lab
🔹 Reported By: #not_specified
🔹 State: 🟢 Resolved
🔹 Disclosed: August 2, 2021, 9:00pm (UTC)
👉 https://hackerone.com/reports/1287574
🔹 Severity: Medium
🔹 Reported To: GitHub Security Lab
🔹 Reported By: #not_specified
🔹 State: 🟢 Resolved
🔹 Disclosed: August 2, 2021, 9:00pm (UTC)
Java: Unsafe deserialization with Jackson
👉 https://hackerone.com/reports/1287573
🔹 Severity: High | 💰 4,500 USD
🔹 Reported To: GitHub Security Lab
🔹 Reported By: #artem
🔹 State: 🟢 Resolved
🔹 Disclosed: August 2, 2021, 9:00pm (UTC)
👉 https://hackerone.com/reports/1287573
🔹 Severity: High | 💰 4,500 USD
🔹 Reported To: GitHub Security Lab
🔹 Reported By: #artem
🔹 State: 🟢 Resolved
🔹 Disclosed: August 2, 2021, 9:00pm (UTC)
Improper Sanitization leads to XSS Fire on admin panel
👉 https://hackerone.com/reports/1011888
🔹 Severity: High
🔹 Reported To: Informatica
🔹 Reported By: #montypythin
🔹 State: 🟢 Resolved
🔹 Disclosed: August 3, 2021, 11:32am (UTC)
👉 https://hackerone.com/reports/1011888
🔹 Severity: High
🔹 Reported To: Informatica
🔹 Reported By: #montypythin
🔹 State: 🟢 Resolved
🔹 Disclosed: August 3, 2021, 11:32am (UTC)
Information disclosure - Feedback is accessible on Public profile even after 'disallowed' at https://hackerone.com/settings/feedback
👉 https://hackerone.com/reports/1264725
🔹 Severity: Low | 💰 500 USD
🔹 Reported To: HackerOne
🔹 Reported By: #brdoors3
🔹 State: 🟢 Resolved
🔹 Disclosed: August 3, 2021, 6:43pm (UTC)
👉 https://hackerone.com/reports/1264725
🔹 Severity: Low | 💰 500 USD
🔹 Reported To: HackerOne
🔹 Reported By: #brdoors3
🔹 State: 🟢 Resolved
🔹 Disclosed: August 3, 2021, 6:43pm (UTC)