HackerOne reports escalation to JIRA is CSRF vulnerable
Medium
H
HackerOne
Submitted None
Actions:
Reported by
whhackersbr
Vulnerability Details
Technical details and impact analysis
**Summary:**
HackerOne reports escalation to JIRA is CSRF vulnerable
**Description (Include Impact):**
An attacker can steal private reports details through a CSRF in HackerOne report escalation to JIRA implementation.
### CSRF
GET https://hackerone.com/reports/[REPORT_NUMBER]/escalate
### Optional: Supporting Material/References (Screenshots)
* https://youtu.be/N6JSGA_RIV4
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$500.00
Submitted
Weakness
Cross-Site Request Forgery (CSRF)