Private program disclosure of `██████████` through notifications

Disclosed: 2021-06-09 01:37:18 By h13- To security
Low
Vulnerability Details
**Summary:** Private program disclosure of `██████` through notifications **Description:** It looks like there is a private program called ████████ - https://hackerone.com/████████ which I'm not yet invited yet. However, I received a notification alert in my H1 account notification box indicating the private program has posted a new message. ### Steps To Reproduce 1. Logged into my H1 account. 2. Observed the below message in notification box ███ Also navigated to https://hackerone.com/notifications and was able to see the notification there as well. ████████ ## Impact It seems like there is a private program called █████████ - https://hackerone.com/████ which I'm not yet invited yet. However, I received a notification alert in my H1 account notification box indicating the private program has posted a new message. This indicates that there is a private program called https://hackerone.com/████ Thanks, @h13-
Actions
View on HackerOne
Report Stats
  • Report ID: 1179241
  • State: Closed
  • Substate: resolved
  • Upvotes: 58
Share this report