2fa can't be activated on app.pullrequest.com

Disclosed: 2024-07-11 15:20:45 By iam_srpk To security
None
Vulnerability Details
**Summary:** Hello Team, Since you are using deprecated google chart API service (which doesn't work now) for generating 2fa qr code image, users cannot setup 2fa for securing account. ### Steps To Reproduce 1. Log into https://app.pullrequest.com 2. Go to "User Settings" -> "Security" -> "Two-Factor Authentication" 3. You cannot when you try enabling it ## Impact I understand it is kinda technical bug. But I decided to report as it literally affects all existing and new users by not allowing them to secure their account.
Actions
View on HackerOne
Report Stats
  • Report ID: 2463069
  • State: Closed
  • Substate: informative
  • Upvotes: 19
Share this report