Private Program and bounty details disclosed as part of JSON search response

Disclosed: 2015-08-31 04:10:14 By techguynoob To security
Unknown
Vulnerability Details
Hello Hackerone Team !!!! Few days ago ████ invited me for Private disclose !!! Yesterday I saw fix of this report #80597 So,I deepdigger the JSON serach Response for example I search this directory https://hackerone.com/████ https://hackerone.com/████; Now I access without authentication and i saw the private Program bounty details disclosed as part of JSON search response !!! ,So I assume its a register as private program in hackerone !!! Response : `████base_bounty:████$` `████base_bounty:████$`
Actions
View on HackerOne
Report Stats
  • Report ID: 80936
  • State: Closed
  • Substate: resolved
  • Upvotes: 3
Share this report