Bug Bounty

Tue
30
Jun

Pinterest Bug Bounty 2015 - Persistent Vulnerability in Contact_Name (API)

Pinterest Bug Bounty 2015 - Persistent Vulnerability in Contact_Name (API)

Today a new pinterest api vulnerability was discovered by the official vulnerability laboratory core team. The issue has medium severity and affects the communication layer of the pinterest network and online-service application.

Tue
09
Jun

Heroku Bug Bounty 2015 (API) - Re Auth Session Token Bypass Vulnerability

Heroku Bug Bounty 2015 (API) - Re Auth Session Token Bypass Web Vulnerability

An application-side re-auth session bypass vulnerability has been discovered in the official heroku API & web-application service. The vulnerability allows an attacker to request unauthorized information without the second forced re authentication module.

The heroku web-service provides to all web services an expire session function that disallows to visit the page without re authentication. The dataclips page session of the editor and the postgres service allows to add for example new context. If the session expires in the main heroku web-service the user will be forced to login again. 

Pages

Subscribe to RSS - Bug Bounty