Information Disclosure which violate program privacy
Low
H
HackerOne
Submitted None
Actions:
Reported by
eqbang
Vulnerability Details
Technical details and impact analysis
**Summary:**
please refer to the following report:
https://hackerone.com/reports/311289
It was noticed that TTS changed the summary and set the domain to example.gov as not to reveal to the public. But at the bottom of the page, "britta changed the scope from https://ci.fr.cloud.gov to None."
Recommendation:
Should only provide general message for such situation: "britta changed the scope"
## Impact
not much of impact. but violate Confidentiality of the program.
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Privacy Violation