Private program disclosure through notifications

Disclosed: 2021-08-05 18:42:15 By sunil_yedla To security
Low
Vulnerability Details
Hello Team, **Summary:** I recently came across hackerone report: https://hackerone.com/reports/1179241 . I though this was fixed but today I have have faced similar experience. I have received a Scope and policy update from the program "██████" which I am not part of. ████████ When I was clicking on the notifications, scope update notification is taking me to hacktivity page and policy update notification is taking me to "Page not found page", I think the previous fix to #1179241 is not complete . As a proof, I have attached a video poc and screenshots. ### Steps To Reproduce 1. Login to Hackerone account 2. Checked my notifications ## POC ██████████ ## Impact I was able to received notification updates of a private program to which I am not part of. This discloses the private program handle to which i am not part of.
Actions
View on HackerOne
Report Stats
  • Report ID: 1234746
  • State: Closed
  • Substate: resolved
  • Upvotes: 36
Share this report