Cookie Consent by Free Privacy Policy Generator ๐Ÿ“Œ HackerOne: Names not completely redacted despite "Redact the names of the involved users" is selected

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š HackerOne: Names not completely redacted despite "Redact the names of the involved users" is selected


๐Ÿ’ก Newskategorie: Sicherheitslรผcken
๐Ÿ”— Quelle: vulners.com


image
Summary: Hi @security @zerotea, Hope you are doing well. Today I have found a special edge case where the names are still visible despite "Redact the names of the involved users" is selected on export as .pdf report. This is similar to the resolved reports #2109009 and #2054222. But this time, looks like the root cause is coming from a team member that triggers the agreed on going public and report became public activity on the report but did not leave any single comment on the report, I have found that when the involve user (names) of a team member that did not put any comments but he is the one who agreed to disclose this report, then his name will be visible on the report despite the "Redact the names of the involved users" is selected Please note that just observed that today because of this disclosed report today from @linkedin: Disclosed Rerport: Improper access control on Linkedin Page While reading that report, i tried to export that as .pdf and I selected the option Redact the names of the involved users, then I saw that the name of the team member who agreed to disclose report report is still visible on the activity. Name: Emmanuel L. Steps To Reproduce Go to this disclosed report from LinkedIn: https://hackerone.com/reports/1587246 Export the report as .pdf , make sure to select the Redact the names of the involved users Check the report output and you will see below acitivity Emmanuel L. 2023-08-24 02:42 report became public Public Emmanuel L. 2023-08-24... ...



๐Ÿ“Œ HackerOne: Names not completely redacted despite "Redact the names of the involved users" is selected


๐Ÿ“ˆ 158.16 Punkte

๐Ÿ“Œ An important system on project [REDACTED] was all [REDACTED] up


๐Ÿ“ˆ 48.05 Punkte

๐Ÿ“Œ HackerOne: Reflected XSS on www.hackerone.com and resources.hackerone.com


๐Ÿ“ˆ 37.87 Punkte

๐Ÿ“Œ HackerOne: Password not checked when disabling 2FA on HackerOne


๐Ÿ“ˆ 30.65 Punkte

๐Ÿ“Œ HackerOne rewards bughunter who found critical security hole inโ€ฆ HackerOne


๐Ÿ“ˆ 25.25 Punkte

๐Ÿ“Œ HackerOne: Open Redirection in [https://www.hackerone.com/index.php]


๐Ÿ“ˆ 25.25 Punkte

๐Ÿ“Œ HackerOne: Any user with access to program can resume and suspend HackerOne Gateway


๐Ÿ“ˆ 25.25 Punkte

๐Ÿ“Œ HackerOne: Subdomain takeover of resources.hackerone.com


๐Ÿ“ˆ 25.25 Punkte

๐Ÿ“Œ HackerOne: Reflected XSS on www.hackerone.com via Wistia embed code


๐Ÿ“ˆ 25.25 Punkte

๐Ÿ“Œ HackerOne: Hacker email disclosed on submission at hackerone hactivity


๐Ÿ“ˆ 25.25 Punkte

๐Ÿ“Œ HackerOne: Blind Stored XSS in HackerOne's Sal 4.1.4.2149 (sal.โ–ˆโ–ˆโ–ˆโ–ˆ.com)


๐Ÿ“ˆ 25.25 Punkte

๐Ÿ“Œ HackerOne: HackerOne Jira integration plugin Leaked JWT to unauthorized jira users


๐Ÿ“ˆ 25.25 Punkte

๐Ÿ“Œ HackerOne: HackerOne Undisclosed Report Leak via PoC of Full Disclosure on Hacktivity


๐Ÿ“ˆ 25.25 Punkte

๐Ÿ“Œ HackerOne: HTML injection that may lead to XSS on HackerOne.com through H1 Triage Wizard Chrome Extension


๐Ÿ“ˆ 25.25 Punkte

๐Ÿ“Œ HackerOne: Hackers two email disclosed on submission at hackerone hactivity


๐Ÿ“ˆ 25.25 Punkte

๐Ÿ“Œ HackerOne: Bypass of #2035332 RXSS at image.hackerone.live via the `url` parameter


๐Ÿ“ˆ 25.25 Punkte

๐Ÿ“Œ HackerOne: Takeover of hackerone.engineering via Github


๐Ÿ“ˆ 25.25 Punkte

๐Ÿ“Œ HackerOne: Unreleased Hackerone Copilot is vulnerable to IDOR


๐Ÿ“ˆ 25.25 Punkte

๐Ÿ“Œ Lubuntu on flash drive not booting up on some devices, EFI sees it, but when selected, it boots to other system anyway.


๐Ÿ“ˆ 24.65 Punkte

๐Ÿ“Œ HackerOne: [Bypass #645264] Report title disclosure despite the program settings for email notification is set to "No Content"


๐Ÿ“ˆ 24.61 Punkte

๐Ÿ“Œ Redacted Report On The Investigation Into Russian Interference In The 2016 Presidential Election


๐Ÿ“ˆ 24.03 Punkte

๐Ÿ“Œ The (Redacted) Mueller Report: First Takes from the Experts


๐Ÿ“ˆ 24.03 Punkte

๐Ÿ“Œ Redacted.ch: privates BitTorrent-Portal mit technischen Problemen


๐Ÿ“ˆ 24.03 Punkte

๐Ÿ“Œ Google Pixel flaw allowed recovery of redacted, cropped images


๐Ÿ“ˆ 24.03 Punkte

๐Ÿ“Œ Privacy fail: Pictures cropped, redacted by Google Pixel phones can be recovered


๐Ÿ“ˆ 24.03 Punkte

๐Ÿ“Œ aCropalypse now! Cropped and redacted images suffer privacy fail on Google Pixel smartphones


๐Ÿ“ˆ 24.03 Punkte

๐Ÿ“Œ Check out the free spooky fan game Aliens: Redacted


๐Ÿ“ˆ 24.03 Punkte

๐Ÿ“Œ FBI Releases (Redacted) Documents About The San Bernardino iPhone Case


๐Ÿ“ˆ 24.03 Punkte

๐Ÿ“Œ FBI Releases (Redacted) Documents About The San Bernardino iPhone Case


๐Ÿ“ˆ 24.03 Punkte

๐Ÿ“Œ Sextortion Scams Using Redacted Phone Numbers to Demand Payment


๐Ÿ“ˆ 24.03 Punkte

๐Ÿ“Œ Redacted findings point to basic mistakes


๐Ÿ“ˆ 24.03 Punkte

๐Ÿ“Œ Businesses can avoid fines if customer data is encrypted or redacted


๐Ÿ“ˆ 24.03 Punkte

๐Ÿ“Œ Redacted court documents hint at a big Microsoft-Nintendo secret


๐Ÿ“ˆ 24.03 Punkte

๐Ÿ“Œ [redacted] Emerges From Stealth to Help Companies Pursue, Disrupt Adversaries


๐Ÿ“ˆ 24.03 Punkte











matomo