Ausnahme gefangen: SSL certificate problem: certificate is not yet valid ๐Ÿ“Œ HackerOne: Team object in GraphQL disclosed private_comment

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š HackerOne: Team object in GraphQL disclosed private_comment


๐Ÿ’ก Newskategorie: Sicherheitslรผcken
๐Ÿ”— Quelle: vulners.com


image
Summary: Hi Team, Some private(I think) part of GraphQL reveals to us Steps To Reproduce Without authorization https://hackerone.com/graphql POST: {"query":"query { node(id: \\"gid://hackerone/SurveyRatingItem/โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ\\") { ... on SurveyRatingItem{_id,pentester{_id},team{_id},key,private_comment,public_comment,rating,recipient{username,email},subject{... on Report{_id}},survey_rating{_id,team{_id},state,respondent{_id,username,email,pentests{nodes{_id}}}}}}}","variables":{}} {"data":{"node":{"_id":"โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ","pentester":null,"team":null,"key":"scope","private_comment":"โ–ˆโ–ˆโ–ˆโ–ˆ","public_comment":null,"rating":1,"recipient":null,"subject":null,"survey_rating":{"_id":"โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ","team":null,"state":"completed","respondent":{"_id":"โ–ˆโ–ˆโ–ˆโ–ˆ","username":"โ–ˆโ–ˆโ–ˆ","email":null,"pentests":{"nodes":[]}}}}}} As we can see, the key field takes the value scope, we don't see in which program this happens, but we can see the comments of the participant, and as we can see, it has the status private PS. Yes, we do not see some data, but in the future they may be disclosed in the comments (I think so) Impact disclosed... ...



๐Ÿ“Œ HackerOne: Team object in GraphQL disclosed private_comment


๐Ÿ“ˆ 95.86 Punkte

๐Ÿ“Œ HackerOne: Team object in GraphQL disclosed of private programs via the industry


๐Ÿ“ˆ 56.9 Punkte

๐Ÿ“Œ HackerOne: Unauthorized user can obtain `report_sources` attribute through Team GraphQL object


๐Ÿ“ˆ 43.55 Punkte

๐Ÿ“Œ Creating a GraphQL Server, Part 1: Building a GraphQL Server with Apollo GraphQL


๐Ÿ“ˆ 43.09 Punkte

๐Ÿ“Œ Intro to GraphQL, Part 1: What is GraphQL | Learning GraphQL


๐Ÿ“ˆ 43.09 Punkte

๐Ÿ“Œ Intro to GraphQL, Part 2: Exploring a GraphQL Endpoint | Learning GraphQL


๐Ÿ“ˆ 43.09 Punkte

๐Ÿ“Œ HackerOne: Hacker email disclosed on submission at hackerone hactivity


๐Ÿ“ˆ 38.56 Punkte

๐Ÿ“Œ HackerOne: Hackers two email disclosed on submission at hackerone hactivity


๐Ÿ“ˆ 38.56 Punkte

๐Ÿ“Œ HackerOne: Reflected XSS on www.hackerone.com and resources.hackerone.com


๐Ÿ“ˆ 37.82 Punkte

๐Ÿ“Œ From REST To GraphQL (aka GraphQL in Production)


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ Creating a GraphQL Server, Part 3: Publishing a GraphQL Server to Azure Functions


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ Creating a GraphQL Server, Part 2: Publishing a GraphQL Server to Azure App Service


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ Intro to GraphQL, Part 2: Exploring a GraphQL Endpoint


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ Intro to GraphQL, Part 1: What is GraphQL


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ Curious Use Cases of GraphQL (and The Future of GraphQL)


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ MicroProfile GraphQL 1.0 bietet APIs fรผr Java-Applikationen auf GraphQL-Basis


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ GraphQL, Simplified (GraphQL-hooks Workshop)


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ Mirumee Saleor 2.0.0 GraphQL API /graphql/ information disclosure


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ Putting The Graph In GraphQL With The Neo4j GraphQL Library


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ CVE-2023-28867 | graphql-java GraphQL Query stack-based overflow


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ CVE-2023-28877 | VTEX apps-graphql 2.x GraphQL API Module improper authorization


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ How To Get Type-Safety Frontend Queries Like GraphQL Without GraphQL Using Typescript


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ Unlocking the Power of GraphQL for Beginners: A Step-by-Step Guide to Integrating GraphQL into Your Existing Project


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ CVE-2023-50730 | graphql/grackle GraphQL Query stack-based overflow


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ heise+ | GraphQL-APIs mit GraphQL Editor designen


๐Ÿ“ˆ 28.73 Punkte

๐Ÿ“Œ CVE-2022-44108 | pdftojson 94204bb Object.cc Object::copy(Object*) stack-based overflow


๐Ÿ“ˆ 27.9 Punkte

๐Ÿ“Œ HackerOne: Confidential data of users and limited metadata of programs and reports accessible via GraphQL


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ HackerOne: Private information exposed through GraphQL filters


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ HackerOne: Private program disclosure via `vpn_suspended` GraphQL query


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ HackerOne: Disclosure of `payment_transactions` for programs via GraphQL query


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ HackerOne: Email address of any user can be queried on Report Invitation GraphQL type when username is known


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ HackerOne: Graphql: Sorting the reports by jira_status field resulted to different value


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ HackerOne: Private information exposed through GraphQL search endpoints aggregates


๐Ÿ“ˆ 26.97 Punkte

๐Ÿ“Œ HackerOne: IDOR - Delete all Licenses and certifications from users account using CreateOrUpdateHackerCertification GraphQL query


๐Ÿ“ˆ 26.97 Punkte











matomo