User with Read-Only permissions can manually public disclosure the report
Unknown
Vulnerability Details
Hello,
I would like to report an incomplete fix of #109483 this report .manually disclose functionality is not consider for fix that cause read-only team members to post a public comment.
In hackerone public disclose have a three types
1.Team/User Request a public disclose a bug
2.Team/user Agree a public disclose a bug
3.Team member Manually public disclose a bug
Poc :
1.Login into Program(testbug) as owner account
2.Create a new group with "Report" Permission . Add a user to that group
3.Create a new group with "Read-only" Permission . Add a user to that group
3.Login into user account Report a bug to Program (testbug)
4."Report" Permission User closed a bug to Resolved and ask for "Public disclose"
5."Read-only" Permission user able to "Manually public disclose" a bug .
Regards,
Techguynoob
Actions
View on HackerOneReport Stats
- Report ID: 118718
- State: Closed
- Substate: resolved
- Upvotes: 2