Email enumeration of users

Disclosed: 2019-03-05 08:20:50 By pappan To homebrew
Medium
Vulnerability Details
In https://jenkins.brew.sh/user/latish1337/api/xml, I was able to see latish1337 users' email address. Hence, its possible to see the email of all the users listed in the https://jenkins.brew.sh/user/. {F176835}
Actions
View on HackerOne
Report Stats
  • Report ID: 221869
  • State: Closed
  • Substate: resolved
  • Upvotes: 140
Share this report