Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [
- {
- u'swag':False,
- u'voters':[
- u'sameerphad72'
- ],
- u'substate':u'not-applicable',
- u'title':u'Global defaming of any twitter user',
- u'url':u'/reports/434689',
- u'latest_disclosable_activity_at': u'2018-12-06T23:43:48.689 Z',
- u'reporter':{
- u'username':u'csanuragjain',
- u'url':u'/csanuragjain',
- u'id':58139
- },
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'critical',
- u'bounty_disclosed':True,
- u'vote_count':1,
- u'team':{
- u'url':u'/twitter',
- u'profile':{
- u'name':u'Twitter'
- },
- u'handle':u'twitter',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/000/061/4acfe72859c5e9cb48a152edb4e498e13fa28df2_small.?1439954730',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/000/061/e78ef26a3191adcabe7311daa107bd9e152d3b5c_medium.?1439954730'
- }
- },
- u'requires_view_privilege':False,
- u'id':434689,
- u'readable_substate':u'N/A'
- },
- {
- u'swag':False,
- u'voters':[
- u'sp1d3rs',
- u's_p_q_r',
- u'ak1t4',
- u'mygf',
- u'mobius07',
- u'null-byte',
- u'japz',
- u'zhaker0ne-bbh',
- u'mrr3boot',
- u'cryptographer',
- u'and 1 more...'
- ],
- u'substate':u'resolved',
- u'reporter':{
- u'username':u'vijay_kumar1110',
- u'url':u'/vijay_kumar1110',
- u'id':16230
- },
- u'url':u'/reports/154405',
- u'latest_disclosable_activity_at': u'2018-12-06T15:04:05.411 Z',
- u'title':u'Read access to hidden orders,
- products,
- customers etc. by limited access Staff member through reference page in Comments (Information disclosure )',
- u'total_awarded_bounty_amount':u'500.00',
- u'latest_disclosable_action':u'disclosed',
- u'bounty_disclosed':True,
- u'vote_count':11,
- u'team':{
- u'url':u'/shopify',
- u'profile':{
- u'name':u'Shopify'
- },
- u'handle':u'shopify',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/001/382/1e9872bf9cfe04008c2673e07bfecaa83858cca1_small.jpg?1532728703',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/001/382/30421c25f4a7b03ec3250e36efb64f7291402806_medium.jpg?1532728703'
- }
- },
- u'requires_view_privilege':False,
- u'id':154405,
- u'formatted_bounty':u'$500',
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'emitrani',
- u'eveeez',
- u'lincoln9932',
- u'pisarenko',
- u'babayaga_',
- u'mygf',
- u'cryptographer',
- u'sameerphad72',
- u'pkemni',
- u'o2204922'
- ],
- u'substate':u'resolved',
- u'title':u'reflected XSS avito.ru',
- u'url':u'/reports/344429',
- u'latest_disclosable_activity_at': u'2018-12-06T09:45:27.803 Z',
- u'reporter':{
- u'username':u'lincoln9932',
- u'url':u'/lincoln9932',
- u'id':49373
- },
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'medium',
- u'bounty_disclosed':True,
- u'vote_count':10,
- u'team':{
- u'url':u'/avito',
- u'profile':{
- u'name':u'Avito'
- },
- u'handle':u'avito',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/016/112/d0c32255a937980f8f8d03d56115ffeae2c731b5_small.?1478019451',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/016/112/80fe1136be7f39fdc571d088a583366d475f33cb_medium.?1478019451'
- }
- },
- u'requires_view_privilege':False,
- u'id':344429,
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'muon4',
- u'eveeez',
- u'0xhelloworld',
- u'an0nym0us',
- u'ak1t4',
- u'th3plumb3r',
- u'babayaga_',
- u'mygf',
- u'c1231665',
- u'ankitsingh',
- u'and 25 more...'
- ],
- u'substate':u'resolved',
- u'title': u'Account takeover at https://try.discourse.org due to no CSRF protection in connecting Yahoo account',
- u'url':u'/reports/423022',
- u'latest_disclosable_activity_at': u'2018-12-06T02:35:56.704 Z',
- u'reporter':{
- u'username':u'avinash_',
- u'url':u'/avinash_',
- u'id':173906
- },
- u'total_awarded_bounty_amount':u'512.00',
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'high',
- u'bounty_disclosed':True,
- u'vote_count':35,
- u'team':{
- u'url':u'/discourse',
- u'profile':{
- u'name':u'Discourse'
- },
- u'handle':u'discourse',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/016/893/3dd37e1cfa3d9380ced573b87beae0c950703ddd_small.?1481849067',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/016/893/2ee366d05b47833a98f06c29cd5318d1bb134e20_medium.?1481849067'
- }
- },
- u'requires_view_privilege':False,
- u'id':423022,
- u'formatted_bounty':u'$512',
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'bjeanes',
- u'bl4de',
- u'0x9090',
- u'eveeez',
- u'an0nym0us',
- u'th3plumb3r',
- u'babayaga_',
- u'mygf',
- u'craxerbikash',
- u'cryptographer',
- u'and 2 more...'
- ],
- u'substate':u'resolved',
- u'title':u'Specially constructed multi-part requests cause multi-second response times; vulnerable to DoS',
- u'url':u'/reports/431561',
- u'latest_disclosable_activity_at': u'2018-12-05T21:46:17.298 Z',
- u'reporter':{
- u'username':u'bjeanes',
- u'url':u'/bjeanes',
- u'id':390819
- },
- u'total_awarded_bounty_amount':u'1500.00',
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'medium',
- u'bounty_disclosed':True,
- u'vote_count':12,
- u'team':{
- u'url':u'/rails',
- u'profile':{
- u'name':u'Ruby on Rails'
- },
- u'handle':u'rails',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/000/022/2883e997d5f9ddf2f1c31365d74abe52fc54c9c9_small.png?1383736680',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/000/022/1b2dab688cae8b769493f39137f09274a6b5f156_medium.png?1383736680'
- }
- },
- u'requires_view_privilege':False,
- u'id':431561,
- u'formatted_bounty':u'$1,
- 500 ', u' readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'eveeez',
- u'th3plumb3r',
- u'babayaga_',
- u'mygf',
- u'craxerbikash',
- u'japz',
- u'asad_anwar',
- u'cryptographer',
- u'sameerphad72',
- u'sveh'
- ],
- u'substate':u'resolved',
- u'title':u'Reflected XSS of bbe-child-starter Theme via "value"-GET-parameter',
- u'url':u'/reports/335735',
- u'latest_disclosable_activity_at': u'2018-12-05T08:07:56.874 Z',
- u'reporter':{
- u'username':u'chihuahua',
- u'url':u'/chihuahua',
- u'id':238742
- },
- u'total_awarded_bounty_amount':u'250.00',
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'high',
- u'bounty_disclosed':True,
- u'vote_count':10,
- u'team':{
- u'url':u'/localtapiola',
- u'profile':{
- u'name':u'LocalTapiola'
- },
- u'handle':u'localtapiola',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/008/416/23d72f4d3433458578a2ce1b4cc7574a935e2316_small.png?1457688936',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/008/416/b913929e71e6e373cc437dbd4c96b7df758fdbe6_medium.png?1457688936'
- }
- },
- u'requires_view_privilege':False,
- u'id':335735,
- u'formatted_bounty':u'$250',
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'bl4de',
- u'spam404',
- u'hunter',
- u'balis0ng',
- u's_p_q_r',
- u'mik317',
- u'0xc0ffee',
- u'flashdisk',
- u'theappsec',
- u'asad0x01_',
- u'and 50 more...'
- ],
- u'substate':u'resolved',
- u'title':u'A user can bypass approval step in Hacker Publishing feature,
- allowing them to publish reports immediately',
- u'url':u'/reports/452959',
- u'latest_disclosable_activity_at': u'2018-12-05T04:55:40.413 Z',
- u'reporter':{
- u'username':u'haxta4ok00',
- u'url':u'/haxta4ok00',
- u'id':49175
- },
- u'total_awarded_bounty_amount':u'2500.00',
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'medium',
- u'bounty_disclosed':True,
- u'vote_count':60,
- u'team':{
- u'url':u'/security',
- u'profile':{
- u'name':u'HackerOne'
- },
- u'handle':u'security',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/000/013/68fea1fe00dc833f4109e015738af4b374727e56_small.png?1445331713',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/000/013/28af2ada2cc00aa9427504fc5a14f587362df84b_medium.png?1445331713'
- }
- },
- u'requires_view_privilege':False,
- u'id':452959,
- u'formatted_bounty':u'$2,
- 500 ', u' readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'eveeez',
- u'13ern',
- u'babayaga_',
- u'mygf',
- u'spetr0x',
- u'cryptographer',
- u'sameerphad72'
- ],
- u'substate':u'resolved',
- u'title':u'Imperfect CSRF To Overwrite Server Config at /go/admin/restful/configuration/file/POST/xml',
- u'url':u'/reports/240048',
- u'latest_disclosable_activity_at': u'2018-12-05T04:13:54.294 Z',
- u'reporter':{
- u'username':u'4cad',
- u'url':u'/4cad',
- u'id':164214
- },
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'medium',
- u'bounty_disclosed':True,
- u'vote_count':7,
- u'team':{
- u'url':u'/gocd',
- u'profile':{
- u'name':u'GoCD'
- },
- u'handle':u'gocd',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/013/559/70fd3c380ff6241bc4c49df2e6817993fca4657f_small.?1465311808',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/013/559/2eefa9b4223a595138a3617a4cba1082b6eb062d_medium.?1465311808'
- }
- },
- u'requires_view_privilege':False,
- u'id':240048,
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'an0nym0us',
- u'th3plumb3r',
- u'babayaga_',
- u'mygf',
- u'hariharan21',
- u'whitesector',
- u'craxerbikash',
- u'japz',
- u'spetr0x',
- u'cryptographer',
- u'and 6 more...'
- ],
- u'substate':u'resolved',
- u'title':u'Admin Macro Description Stored XSS',
- u'url':u'/reports/392457',
- u'latest_disclosable_activity_at': u'2018-12-05T00:10:17.368 Z',
- u'reporter':{
- u'username':u'hariharan21',
- u'url':u'/hariharan21',
- u'id':315451
- },
- u'total_awarded_bounty_amount':u'250.00',
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'medium',
- u'bounty_disclosed':True,
- u'vote_count':16,
- u'team':{
- u'url':u'/zendesk',
- u'profile':{
- u'name':u'Zendesk'
- },
- u'handle':u'zendesk',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/000/205/ff98ae0255b89059063ba495dd9f3ae4dad0ece1_small.jpg?1502908905',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/000/205/255d1c4e6dfc0b46260481d8f9899e925eb6d879_medium.jpg?1502908905'
- }
- },
- u'requires_view_privilege':False,
- u'id':392457,
- u'formatted_bounty':u'$250',
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'eveeez',
- u'an0nym0us',
- u'axolotl',
- u'haxta4ok00',
- u'babayaga_',
- u'mygf',
- u'cyberunit',
- u'japz',
- u'securityteacher',
- u'smit',
- u'and 8 more...'
- ],
- u'substate':u'resolved',
- u'title':u'Notifications sent due to "Transfer report" functionality may be sent to users who are no longer authorized to see the report',
- u'url':u'/reports/442843',
- u'latest_disclosable_activity_at': u'2018-12-04T19:51:45.336 Z',
- u'reporter':{
- u'username':u'npbhatter17',
- u'url':u'/npbhatter17',
- u'id':154530
- },
- u'total_awarded_bounty_amount':u'500.00',
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'low',
- u'bounty_disclosed':True,
- u'vote_count':18,
- u'team':{
- u'url':u'/security',
- u'profile':{
- u'name':u'HackerOne'
- },
- u'handle':u'security',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/000/013/68fea1fe00dc833f4109e015738af4b374727e56_small.png?1445331713',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/000/013/28af2ada2cc00aa9427504fc5a14f587362df84b_medium.png?1445331713'
- }
- },
- u'requires_view_privilege':False,
- u'id':442843,
- u'formatted_bounty':u'$500',
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'bl4de',
- u'kapytein',
- u'babayaga_',
- u'mygf',
- u'cyberunit',
- u'japz',
- u'cryptographer',
- u'sameerphad72',
- u'jeiie',
- u'1killerqueen',
- u'and 2 more...'
- ],
- u'substate':u'resolved',
- u'title':u'Stored XSS in merge request pages',
- u'url':u'/reports/409380',
- u'latest_disclosable_activity_at': u'2018-12-03T22:15:49.251 Z',
- u'reporter':{
- u'username':u'8ayac',
- u'url':u'/8ayac',
- u'id':266369
- },
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'high',
- u'bounty_disclosed':True,
- u'vote_count':12,
- u'team':{
- u'url':u'/gitlab',
- u'profile':{
- u'name':u'GitLab'
- },
- u'handle':u'gitlab',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/000/264/338ec4b43393873324e3f1911f2f107d025d13f1_small.png?1454722206',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/000/264/f40e550269de1c8aef9adbdfe728c9aa8163a7e5_medium.png?1454722206'
- }
- },
- u'requires_view_privilege':False,
- u'id':409380,
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'bl4de',
- u'kapytein',
- u'geeknik',
- u'tulswani',
- u'babayaga_',
- u'mygf',
- u'kiraak-boy',
- u'cyberunit',
- u'cryptographer',
- u'sameerphad72',
- u'and 6 more...'
- ],
- u'substate':u'resolved',
- u'title':u'Unauthorized users may be able to view almost all informations related to Private projects.',
- u'url':u'/reports/407763',
- u'latest_disclosable_activity_at': u'2018-12-03T22:15:29.758 Z',
- u'reporter':{
- u'username':u'8ayac',
- u'url':u'/8ayac',
- u'id':266369
- },
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'medium',
- u'bounty_disclosed':True,
- u'vote_count':16,
- u'team':{
- u'url':u'/gitlab',
- u'profile':{
- u'name':u'GitLab'
- },
- u'handle':u'gitlab',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/000/264/338ec4b43393873324e3f1911f2f107d025d13f1_small.png?1454722206',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/000/264/f40e550269de1c8aef9adbdfe728c9aa8163a7e5_medium.png?1454722206'
- }
- },
- u'requires_view_privilege':False,
- u'id':407763,
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'spam404',
- u'theappsec',
- u'geeknik',
- u'an0nym0us',
- u'appsecure_in',
- u'th3plumb3r',
- u'hecsv17',
- u'tulswani',
- u'babayaga_',
- u'mygf',
- u'and 42 more...'
- ],
- u'substate':u'resolved',
- u'reporter':{
- u'username':u'sandeep_hodkasia',
- u'url':u'/sandeep_hodkasia',
- u'id':139321
- },
- u'url':u'/reports/419731',
- u'latest_disclosable_activity_at': u'2018-12-03T07:02:09.557 Z',
- u'title':u' [
- www.zomato.com
- ] Blind XSS in one of the Admin Dashboard',
- u'total_awarded_bounty_amount':u'500.00',
- u'latest_disclosable_action':u'disclosed',
- u'bounty_disclosed':True,
- u'vote_count':52,
- u'team':{
- u'url':u'/zomato',
- u'profile':{
- u'name':u'Zomato'
- },
- u'handle':u'zomato',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/002/943/7b54bc7a4a265c47ec0d946a6abf079078b82401_small.png?1526447675',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/002/943/dbb71f3e2a0e73fe819c0c2a3e4fbcdd24d138e9_medium.png?1526447675'
- }
- },
- u'requires_view_privilege':False,
- u'id':419731,
- u'formatted_bounty':u'$500',
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'd0nut',
- u'michiel',
- u'kapytein',
- u'003random',
- u'mik317',
- u'0xc0ffee',
- u'karel_origin',
- u'asad0x01_',
- u'babayaga_',
- u'mygf',
- u'and 8 more...'
- ],
- u'substate':u'resolved',
- u'title':u'Import of repositories from GitHub is tied to username instead of immutable ID',
- u'url':u'/reports/452920',
- u'latest_disclosable_activity_at': u'2018-12-02T16:42:41.442 Z',
- u'reporter':{
- u'username':u'emitrani',
- u'url':u'/emitrani',
- u'id':206181
- },
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'low',
- u'bounty_disclosed':True,
- u'vote_count':18,
- u'team':{
- u'url':u'/liberapay',
- u'profile':{
- u'name':u'Liberapay'
- },
- u'handle':u'liberapay',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/028/411/0782331e0ae0dfac7617ae2c5cc5f275a4a84ebe_small.?1524732576',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/028/411/eb1bc1321b1b84c9057c721f5705b51a93438fe2_medium.?1524732576'
- }
- },
- u'requires_view_privilege':False,
- u'id':452920,
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'spam404',
- u'asad0x01_',
- u'ischleep',
- u'ashish_r_padelkar',
- u'an0nym0us',
- u'axolotl',
- u'michan001',
- u'haxta4ok00',
- u'babayaga_',
- u'mygf',
- u'and 18 more...'
- ],
- u'substate':u'resolved',
- u'title': u'Revoking user session in https://hackerone.com/settings/sessions does not revoke the GraphQL query session',
- u'url':u'/reports/417382',
- u'latest_disclosable_activity_at': u'2018-11-30T19:21:17.524 Z',
- u'reporter':{
- u'username':u'japz',
- u'url':u'/japz',
- u'id':78347
- },
- u'total_awarded_bounty_amount':u'500.00',
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'low',
- u'bounty_disclosed':True,
- u'vote_count':28,
- u'team':{
- u'url':u'/security',
- u'profile':{
- u'name':u'HackerOne'
- },
- u'handle':u'security',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/000/013/68fea1fe00dc833f4109e015738af4b374727e56_small.png?1445331713',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/000/013/28af2ada2cc00aa9427504fc5a14f587362df84b_medium.png?1445331713'
- }
- },
- u'requires_view_privilege':False,
- u'id':417382,
- u'formatted_bounty':u'$500',
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'mygf',
- u'tiger24',
- u'sameerphad72'
- ],
- u'substate':u'resolved',
- u'title':u'Prototype pollution attack in node.extend',
- u'url':u'/reports/430831',
- u'latest_disclosable_activity_at': u'2018-11-30T14:01:57.506 Z',
- u'reporter':{
- u'username':u'asgerf',
- u'url':u'/asgerf',
- u'id':302864
- },
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'low',
- u'bounty_disclosed':True,
- u'vote_count':3,
- u'team':{
- u'url':u'/nodejs-ecosystem',
- u'profile':{
- u'name':u'Node.js third-party modules'
- },
- u'handle':u'nodejs-ecosystem',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/023/949/309112251b444244d95977d1299148aae6482789_small.?1508679627',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/023/949/c1f5f15ac094c1327c13dd19f55dbcb7411272bd_medium.?1508679627'
- }
- },
- u'requires_view_privilege':False,
- u'id':430831,
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'mygf',
- u'spetr0x',
- u'cryptographer',
- u'sameerphad72',
- u'santino'
- ],
- u'substate':u'resolved',
- u'reporter':{
- u'username':u'kiraak-boy',
- u'url':u'/kiraak-boy',
- u'id':37547
- },
- u'url':u'/reports/151680',
- u'latest_disclosable_activity_at': u'2018-11-30T13:51:55.712 Z',
- u'title':u'Possible SSRF at URL Parameter while creating a new package repository',
- u'latest_disclosable_action':u'disclosed',
- u'bounty_disclosed':True,
- u'vote_count':5,
- u'team':{
- u'url':u'/gocd',
- u'profile':{
- u'name':u'GoCD'
- },
- u'handle':u'gocd',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/013/559/70fd3c380ff6241bc4c49df2e6817993fca4657f_small.?1465311808',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/013/559/2eefa9b4223a595138a3617a4cba1082b6eb062d_medium.?1465311808'
- }
- },
- u'requires_view_privilege':False,
- u'id':151680,
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'mygf',
- u'0x08',
- u'spetr0x',
- u'cryptographer',
- u'sameerphad72',
- u'axif',
- u'santino',
- u'm_chennaiindia',
- u'niko-red'
- ],
- u'substate':u'resolved',
- u'reporter':{
- u'username':u'kiraak-boy',
- u'url':u'/kiraak-boy',
- u'id':37547
- },
- u'url':u'/reports/151678',
- u'latest_disclosable_activity_at': u'2018-11-30T13:36:41.067 Z',
- u'title':u'Cross Site Scripting',
- u'latest_disclosable_action':u'disclosed',
- u'bounty_disclosed':True,
- u'vote_count':9,
- u'team':{
- u'url':u'/gocd',
- u'profile':{
- u'name':u'GoCD'
- },
- u'handle':u'gocd',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/013/559/70fd3c380ff6241bc4c49df2e6817993fca4657f_small.?1465311808',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/013/559/2eefa9b4223a595138a3617a4cba1082b6eb062d_medium.?1465311808'
- }
- },
- u'requires_view_privilege':False,
- u'id':151678,
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'mygf',
- u'sameerphad72',
- u'niko-red'
- ],
- u'substate':u'duplicate',
- u'reporter':{
- u'username':u'kiraak-boy',
- u'url':u'/kiraak-boy',
- u'id':37547
- },
- u'url':u'/reports/151779',
- u'latest_disclosable_activity_at': u'2018-11-30T13:34:51.542 Z',
- u'title':u'Reflected XSS',
- u'latest_disclosable_action':u'disclosed',
- u'bounty_disclosed':True,
- u'vote_count':3,
- u'team':{
- u'url':u'/gocd',
- u'profile':{
- u'name':u'GoCD'
- },
- u'handle':u'gocd',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/013/559/70fd3c380ff6241bc4c49df2e6817993fca4657f_small.?1465311808',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/013/559/2eefa9b4223a595138a3617a4cba1082b6eb062d_medium.?1465311808'
- }
- },
- u'requires_view_privilege':False,
- u'id':151779,
- u'readable_substate':u'Duplicate'
- },
- {
- u'swag':False,
- u'voters':[
- u'mygf',
- u'smit',
- u'cryptographer',
- u'sameerphad72',
- u'niko-red'
- ],
- u'substate':u'resolved',
- u'reporter':{
- u'username':u'pradeepch99',
- u'url':u'/pradeepch99',
- u'id':19143
- },
- u'url':u'/reports/151634',
- u'latest_disclosable_activity_at': u'2018-11-30T13:02:46.960 Z',
- u'title': u'XSS in http: //localhost:8153 /go/admin/config/server/update',
- u'latest_disclosable_action':u'disclosed',
- u'bounty_disclosed':True,
- u'vote_count':5,
- u'team':{
- u'url':u'/gocd',
- u'profile':{
- u'name':u'GoCD'
- },
- u'handle':u'gocd',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/013/559/70fd3c380ff6241bc4c49df2e6817993fca4657f_small.?1465311808',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/013/559/2eefa9b4223a595138a3617a4cba1082b6eb062d_medium.?1465311808'
- }
- },
- u'requires_view_privilege':False,
- u'id':151634,
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'tulswani',
- u'babayaga_',
- u'mygf',
- u'sameerphad72'
- ],
- u'substate':u'resolved',
- u'title':u'Prototype Pollution Vulnerability in mpath Package',
- u'url':u'/reports/390860',
- u'latest_disclosable_activity_at': u'2018-11-30T06:21:32.449 Z',
- u'reporter':{
- u'username':u'cris_semmle',
- u'url':u'/cris_semmle',
- u'id':320894
- },
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'high',
- u'bounty_disclosed':True,
- u'vote_count':4,
- u'team':{
- u'url':u'/nodejs-ecosystem',
- u'profile':{
- u'name':u'Node.js third-party modules'
- },
- u'handle':u'nodejs-ecosystem',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/023/949/309112251b444244d95977d1299148aae6482789_small.?1508679627',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/023/949/c1f5f15ac094c1327c13dd19f55dbcb7411272bd_medium.?1508679627'
- }
- },
- u'requires_view_privilege':False,
- u'id':390860,
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'mirchr',
- u'ziot',
- u'jobert',
- u'derision',
- u'spam404',
- u'kapytein',
- u'teknogeek',
- u's_p_q_r',
- u'mik317',
- u'0xc0ffee',
- u'and 98 more...'
- ],
- u'substate':u'resolved',
- u'title':u'SQL injection in GraphQL endpoint through embedded_submission_form_uuid parameter',
- u'url':u'/reports/435066',
- u'latest_disclosable_activity_at': u'2018-11-30T01:26:39.952 Z',
- u'reporter':{
- u'username':u'jobert',
- u'url':u'/jobert',
- u'id':2
- },
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'critical',
- u'bounty_disclosed':True,
- u'vote_count':108,
- u'team':{
- u'url':u'/security',
- u'profile':{
- u'name':u'HackerOne'
- },
- u'handle':u'security',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/000/013/68fea1fe00dc833f4109e015738af4b374727e56_small.png?1445331713',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/000/013/28af2ada2cc00aa9427504fc5a14f587362df84b_medium.png?1445331713'
- }
- },
- u'requires_view_privilege':False,
- u'id':435066,
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'spam404',
- u'kapytein',
- u'asad0x01_',
- u'an0nym0us',
- u'axolotl',
- u'michan001',
- u'modam3r5',
- u'haxta4ok00',
- u'bhavi',
- u'bytehope',
- u'and 20 more...'
- ],
- u'substate':u'resolved',
- u'title':u'Attacker can claim credentials for private program that has a published external program',
- u'url':u'/reports/449680',
- u'latest_disclosable_activity_at': u'2018-11-29T19:43:59.929 Z',
- u'reporter':{
- u'username':u'jobert',
- u'url':u'/jobert',
- u'id':2
- },
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'medium',
- u'bounty_disclosed':True,
- u'vote_count':30,
- u'team':{
- u'url':u'/security',
- u'profile':{
- u'name':u'HackerOne'
- },
- u'handle':u'security',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/000/013/68fea1fe00dc833f4109e015738af4b374727e56_small.png?1445331713',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/000/013/28af2ada2cc00aa9427504fc5a14f587362df84b_medium.png?1445331713'
- }
- },
- u'requires_view_privilege':False,
- u'id':449680,
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'mygf',
- u'sameerphad72'
- ],
- u'substate':u'resolved',
- u'title':u'Prototype pollution attack in just-extend',
- u'url':u'/reports/430291',
- u'latest_disclosable_activity_at': u'2018-11-29T17:13:19.437 Z',
- u'reporter':{
- u'username':u'asgerf',
- u'url':u'/asgerf',
- u'id':302864
- },
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'low',
- u'bounty_disclosed':True,
- u'vote_count':2,
- u'team':{
- u'url':u'/nodejs-ecosystem',
- u'profile':{
- u'name':u'Node.js third-party modules'
- },
- u'handle':u'nodejs-ecosystem',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/023/949/309112251b444244d95977d1299148aae6482789_small.?1508679627',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/023/949/c1f5f15ac094c1327c13dd19f55dbcb7411272bd_medium.?1508679627'
- }
- },
- u'requires_view_privilege':False,
- u'id':430291,
- u'readable_substate':u'Resolved'
- },
- {
- u'swag':False,
- u'voters':[
- u'ak1t4',
- u'mygf',
- u'k_outis',
- u'whitesector',
- u'silv3rpoision',
- u'japz',
- u'base_64',
- u'asad_anwar',
- u'0x08',
- u'omespino',
- u'and 16 more...'
- ],
- u'substate':u'resolved',
- u'title':u'The POODLE attack (SSLv3 supported) at status.slack.com',
- u'url':u'/reports/375097',
- u'latest_disclosable_activity_at': u'2018-11-28T15:20:11.406 Z',
- u'reporter':{
- u'username':u'cryptographer',
- u'url':u'/cryptographer',
- u'id':252131
- },
- u'total_awarded_bounty_amount':u'500.00',
- u'latest_disclosable_action':u'disclosed',
- u'severity_rating':u'medium',
- u'bounty_disclosed':True,
- u'vote_count':26,
- u'team':{
- u'url':u'/slack',
- u'profile':{
- u'name':u'Slack'
- },
- u'handle':u'slack',
- u'profile_picture_urls':{
- u'small': u'https://profile-photos.hackerone-user-content.com/000/000/069/a44d7bfd843f514c723441a5a40daf5bac8e9e38_small.png?1449082084',
- u'medium': u'https://profile-photos.hackerone-user-content.com/000/000/069/50cfd8e05b18bade214847ec5f61dcb9e6c85fa9_medium.png?1449082084'
- }
- },
- u'requires_view_privilege':False,
- u'id':375097,
- u'formatted_bounty':u'$500',
- u'readable_substate':u'Resolved'
- }
- ]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement