usememos/memos Incorrect Use of Privileged APIs vulnerability

In usememos/memos 0.9.0 and prior, a user can archive any private memos, delete any shortcut, and edit any shortcut from other users via API.Read More ...

Continue Reading
GitHub and the Ekoparty 2022 Capture the Flag

As a sponsor of [Ekoparty 2022](), GitHub had the privilege of submitting several challenges to the event's Capture The Flag (CTF) competition. Hubbers from across the company came together to brainst ...

Continue Reading
robbert229/jwt’s token validation methods vulnerable to a timing side-channel during HMAC comparison

Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use this to determine th ...

Continue Reading
intacttechnology.in Cross Site Scripting vulnerability OBB-3124448

Following the coordinated and responsible vulnerability disclosure guidelines of the **[ISO 29147]()** standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. not ...

Continue Reading
imercado.bmfbovespa.com.br Cross Site Scripting vulnerability OBB-3124505

Following the coordinated and responsible vulnerability disclosure guidelines of the **[ISO 29147]()** standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. not ...

Continue Reading
robbert229/jwt’s token validation methods vulnerable to a timing side-channel during HMAC comparison

Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use this to determine th ...

Continue Reading
cadenagramonte.cu Cross Site Scripting vulnerability OBB-3124427

Following the coordinated and responsible vulnerability disclosure guidelines of the **[ISO 29147]()** standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. not ...

Continue Reading
informationphilosopher.com Cross Site Scripting vulnerability OBB-3124460

Following the coordinated and responsible vulnerability disclosure guidelines of the **[ISO 29147]()** standard, Open Bug Bounty has: a. verified the vulnerability and confirmed its existence; b. not ...

Continue Reading

Back to Main

Subscribe for the latest news: