Private data related to program exposed via /reports/<id>.json endpoint to external user participant

Post Reply
Shane1145
Posts: 1836
Joined: Wed Sep 25, 2024 2:31 pm

Private data related to program exposed via /reports/<id>.json endpoint to external user participant

Post by Shane1145 »

An organization has the ability to invite external participants not belonging to their organization to a bug report. The invited user is sees partial data and metadata of a bug in the UI after they accept the invitation. However, in this case I have discovered a way that will make a participant view more data that what is allowed. The data consists of program profile picture, twitter handle, website, about and the asset details to which the report belongs.


https://hackerone.com/reports/2580982
Post Reply