[PATs] Ability to leak comments from issues without ANY "Issues" repo permissions by utilizing "Pull Request" permissions

Disclosed: 2024-01-03 22:52:50 By archangel To github
Medium
Vulnerability Details
No vulnerability description provided or it is restricted.
Actions
View on HackerOne
Report Stats
  • Report ID: 2184950
  • State: Closed
  • Substate: resolved
  • Upvotes: 33
Share this report