"Bounty splitting enabled" can discloses if public VDPs are running private VRP
Low
Vulnerability Details
Hello Everyone,
I hope all is safe and you're safe in this pandemic,
and I hope this won't bother you like my previous submitions lol ,
## _Description_ :
The **"allows_private_disclosure"** resource in team for private team that have a public profile is shown there which discloses that this program have a private VRP if they're enabling "Bounty Splitting" to their private bug bounty program,
I'm not 100% sure cause I accidently found that ████████ shows that they're enabling bounty splitting but they runs a VDPs and that made me think that they're running a private VRP with that ,
████
_______________________________________________________________________________________________________________________
_______________________________________________________________________________________________________________________
## _Steps To Reproduce:_
1. Go to █████████
2. You'll notice that they have bounty splitting option enabled though they're running a VDP
3. This refers that they runs a private VRP with that option enabled
███
**NOTE** : As said in the description I'm not totally sure if this a mistake or an actual bug cause I don't have the ability to try it on my own,
if it's just a mistake giving me the free to self-close this report will be too much apperciatable :)
_______________________________________________________________________________________________________________________
_______________________________________________________________________________________________________________________
## Impact
Ability to know that a team runs an invite only VRP if they're enabling bounty splitting option,
Thanks for taking your valuable time to read and validate this report,
All the best,
Actions
View on HackerOneReport Stats
- Report ID: 1103812
- State: Closed
- Substate: resolved
- Upvotes: 45