GitHub Access Token Exposure
hackerone.com
GitHub Access Token Exposure
1–4 of 4 posts
Re: GitHub Access Token Exposure
#2Just a pretty nice exploit, he got paid 50,000 as a bounty for a simple piece of code with critical impacts.
Re: GitHub Access Token Exposure
#3Title is misleading and it should have (2021) in it too.
Relevant,
Compsci student walks off with $50,000 after bug bounty report blows gaping hole in Shopify software repos (https://www.theregister.com/2021/07/27/shopify_bug_bounty_pa...)
Re: GitHub Access Token Exposure
#4Title is misleading and it should have (2021) in it too. Relevant, Compsci student walks off with $50,000 after bug bounty report blows gaping hole in Shopify software repos ( https://www.theregister.com/2021/07/27/shopify_bug_bounty_pa... )
Yes sorry I saw it and literally clicked the share button to hacker news so I expected it to follow the right submission rules