User with Read-Only permissions can manually public disclosure the report

Disclosed: 2016-04-21 01:55:24 By techguynoob To security
Unknown
Vulnerability Details
Hello, I would like to report an incomplete fix of #109483 this report .manually disclose functionality is not consider for fix that cause read-only team members to post a public comment. In hackerone public disclose have a three types 1.Team/User Request a public disclose a bug 2.Team/user Agree a public disclose a bug 3.Team member Manually public disclose a bug Poc : 1.Login into Program(testbug) as owner account 2.Create a new group with "Report" Permission . Add a user to that group 3.Create a new group with "Read-only" Permission . Add a user to that group 3.Login into user account Report a bug to Program (testbug) 4."Report" Permission User closed a bug to Resolved and ask for "Public disclose" 5."Read-only" Permission user able to "Manually public disclose" a bug . Regards, Techguynoob
Actions
View on HackerOne
Report Stats
  • Report ID: 118718
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report