Private program policy page still accessible after user left the program

Disclosed: 2018-08-12 04:44:08 By japz To security
Medium
Vulnerability Details
Hi Team, **Summary:** I have found a critical sensitive information disclosure, I'm not sure if this is a result of a new hackerone UI update, I observed that some of the UI has been change such as `Hacktivity` etc. __BUG:__ Now all private program policy page together with the updates is visible to me despite i already leave to those private program! __WHOLE POLICY PAGE WAS DISCLOSED:__ Below screenshot is the sample, the private program name is ██████ which i already __LEAVE__ long time ago, but now i can see their policy page! ██████ ## Impact Private program disclcosure.
Actions
View on HackerOne
Report Stats
  • Report ID: 386997
  • State: Closed
  • Substate: resolved
  • Upvotes: 56
Share this report