Able to view hackerone reports attachments
Team Summary
Official summary from GitLab
The reporter found a way to get access to all attachments imported from HackerOne reports with our automation. This included proofs of concept for unpatched vulnerabilities and was rewarded as a critical severity finding given the possibility of leaking unpatched critical severity vulnerabilities. Note that it is intended that https://gitlab.com/gitlab-org/gitlab/-/issues?label_name%5B%5D=HackerOne still shows many fixed vulnerabilities as well as unfixed issues that were deemed low severity enough to be made public. You can learn more about this in the `Disclosure` section of our bug bounty program's policy.
Vulnerability Details
Technical details and impact analysis
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Storage of Sensitive Information