Loading HuntDB...

GitLab - HackerOne Reports

View on HackerOne
248
Total Reports
33
Critical
71
High
86
Medium
41
Low
Weakness: Improper Access Control - Generic
Weakness: Information Disclosure
Weakness: Command Injection - Generic
Bounty: $12000.00

Stored XSS via Kroki diagram

Reported by: vakzz | Disclosed:
High
Weakness: Cross-site Scripting (XSS) - Stored
Bounty: $13950.00
Weakness: Open Redirect
Weakness: Reliance on Untrusted Inputs in a Security Decision
Weakness: Uncontrolled Resource Consumption
Bounty: $1000.00
Weakness: Improper Authentication - Generic
Weakness: Improper Authentication - Generic
Weakness: Violation of Secure Design Principles

SSRF in CI after first run

Reported by: plazmaz | Disclosed:
Medium
Weakness: Server-Side Request Forgery (SSRF)
Weakness: Misconfiguration
Weakness: Open Redirect
Weakness: Privacy Violation
Weakness: Cross-Site Request Forgery (CSRF)
Weakness: Server-Side Request Forgery (SSRF)
Bounty: $4000.00
Weakness: Improper Access Control - Generic
Bounty: $1500.00
Previous Page 2 of 13 Next