REPORTS
PROGRAMS
PUBLISHERS
Now on Twitter
the unofficial
HackerOne
disclosure timeline.
X
b'GitHub Security Lab'
disclosed a bug submitted by
b'jlleitschuh'
b'Java (Maven): Actually fix the use of insecure protocol to download/upload artifacts'
03 Mar 2020
b'New Relic'
disclosed a bug submitted by
b'ashishkataria'
b'Bypassing Protection Mechanism: Change of Account Name after Session Log out '
02 Mar 2020
b'Visma Bug Bounty Program'
disclosed a bug submitted by
b'm0chan'
b'Unrestricted file upload when creating quotes allows for Stored XSS'
02 Mar 2020
b'Showmax'
disclosed a bug submitted by
b'ahmadbrainworks'
b'Open Redirect in secure.showmax.com'
02 Mar 2020
b'Node.js third-party modules'
disclosed a bug submitted by
b'eslam-shieldfy'
b'Server Side Request Forgery in Uppy npm module'
02 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'ayid'
b'Disabled user can reset their password '
01 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'ayid'
b'Nextcloud 10.0 privilege escalation issue - Normal user can mask external storage shared by admin '
01 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'ayid'
b'**minor issue ** -Nextcloud 10.0 session issue with desktop client and android client'
01 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'maprambo'
b'Password of failed (2FA) login attempt is stored in log'
01 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'dalt'
b'Delete All Data of Any User'
01 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'xuesheng'
b'Access to all files of remote user through shared file'
01 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'julzify'
b'WebDAV Empty Property search leads to full CPU usage'
01 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'myster'
b'Broken link for wrong domain entry may be leveraged for Phishing, Misinformation, Serving Malware'
01 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'lukasreschke'
b'DOMPurify 0.8.9 released'
01 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'mmmds'
b'Improper protection of FileContentProvider'
01 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'frankspierings'
b"Unauthenticated 'display name' information leak on enumeration of login names"
01 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'pal434'
b'Missing X-Content-Type-Options '
01 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'5b66c571'
b'Stored XSS on scan.nextcloud.com'
01 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'alpertecimer'
b'Missing SPF flags for customerupdates.nextcloud.com'
01 Mar 2020
b'Nextcloud'
disclosed a bug submitted by
b'maksemuz'
b'Event privacy level does not work in Thunderbird'
01 Mar 2020
1
...
354
355
356
357
358
...
768
BY DENIS WERNER - @NOBBD -
IMPRESSUM