Github Apps can use Scoped-User-To-Server Tokens to Obtain Full Access to User's Projects in Project V2 GraphQL api

Disclosed: 2023-01-26 14:06:20 By ahacker1 To github
High
Vulnerability Details
No vulnerability description provided or it is restricted.
Actions
View on HackerOne
Report Stats
  • Report ID: 1711938
  • State: Closed
  • Substate: resolved
  • Upvotes: 188
Share this report