Private Program and bounty details disclosed as part of JSON search response
Unknown
Vulnerability Details
Hello Hackerone Team !!!!
Few days ago ████ invited me for Private disclose !!!
Yesterday I saw fix of this report #80597
So,I deepdigger the JSON serach Response
for example I search this directory
https://hackerone.com/████
https://hackerone.com/████;
Now I access without authentication and i saw the private Program bounty details disclosed as part of JSON search response !!! ,So I assume its a register as private program in hackerone !!!
Response :
`████base_bounty:████$`
`████base_bounty:████$`
Actions
View on HackerOneReport Stats
- Report ID: 80936
- State: Closed
- Substate: resolved
- Upvotes: 3