<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
<title>HackerOne Hacker Activity</title>
<subtitle>Hacker Activity Filter By Public</subtitle>
<author>
    <name>hackerone.com</name>
</author>
<link href="https://hackerone.com/hacktivity" />
<id>https://hackerone.com/hacktivity</id>


<entry>
  <title>[$150] Nextcloud: PIN bypass in PassCodeActivity via back button</title>
  <link href="https://hackerone.com/reports/3625210" />
  <id>https://hackerone.com/reports/3625210</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3625210">[$150] Nextcloud: PIN bypass in PassCodeActivity via back button</a>]]></content>
</entry>

<entry>
  <title>[$250] Nextcloud: Mail contact autocomplete bypasses administrator-configured user enumeration restrictions and expose member information outside the intended scope</title>
  <link href="https://hackerone.com/reports/3617729" />
  <id>https://hackerone.com/reports/3617729</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3617729">[$250] Nextcloud: Mail contact autocomplete bypasses administrator-configured user enumeration restrictions and expose member information outside the intended scope</a>]]></content>
</entry>

<entry>
  <title>[$150] Nextcloud: Approval app&#39;s file-freshness check can be bypassed by omitting the etag parameter, allowing approval of unreviewed file changes</title>
  <link href="https://hackerone.com/reports/3610332" />
  <id>https://hackerone.com/reports/3610332</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3610332">[$150] Nextcloud: Approval app&#39;s file-freshness check can be bypassed by omitting the etag parameter, allowing approval of unreviewed file changes</a>]]></content>
</entry>

<entry>
  <title>Nextcloud: Improper input validation in emoji field leads to sidebar UI denial of service</title>
  <link href="https://hackerone.com/reports/3599470" />
  <id>https://hackerone.com/reports/3599470</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3599470">Nextcloud: Improper input validation in emoji field leads to sidebar UI denial of service</a>]]></content>
</entry>

<entry>
  <title>[$200] Nextcloud: Arbitrary Board Preference Injection via Deck Config API</title>
  <link href="https://hackerone.com/reports/3599383" />
  <id>https://hackerone.com/reports/3599383</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3599383">[$200] Nextcloud: Arbitrary Board Preference Injection via Deck Config API</a>]]></content>
</entry>

<entry>
  <title>curl: HTTP/1.1 response framing violation and unsafe connection reuse when transfer decoding is disabled</title>
  <link href="https://hackerone.com/reports/4025056" />
  <id>https://hackerone.com/reports/4025056</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/4025056">curl: HTTP/1.1 response framing violation and unsafe connection reuse when transfer decoding is disabled</a>]]></content>
</entry>

<entry>
  <title>curl: Use-after-free of the internal multi-&gt;admin easy handle via the documented CURLMOPT_NOTIFYFUNCTION callback</title>
  <link href="https://hackerone.com/reports/4033971" />
  <id>https://hackerone.com/reports/4033971</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/4033971">curl: Use-after-free of the internal multi-&gt;admin easy handle via the documented CURLMOPT_NOTIFYFUNCTION callback</a>]]></content>
</entry>

<entry>
  <title>curl: TELNET control and environment data bypass HTTPS-proxy TLS</title>
  <link href="https://hackerone.com/reports/4021960" />
  <id>https://hackerone.com/reports/4021960</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/4021960">curl: TELNET control and environment data bypass HTTPS-proxy TLS</a>]]></content>
</entry>

<entry>
  <title>Nextcloud: files_lock: a write-share collaborator can place a TYPE_TOKEN lock that permanently denies the file owner, survives share revocation and account delet</title>
  <link href="https://hackerone.com/reports/3770482" />
  <id>https://hackerone.com/reports/3770482</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3770482">Nextcloud: files_lock: a write-share collaborator can place a TYPE_TOKEN lock that permanently denies the file owner, survives share revocation and account delet</a>]]></content>
</entry>

<entry>
  <title>Nextcloud: Persistent SMTP header injection via identity `organization` / `name`</title>
  <link href="https://hackerone.com/reports/3913012" />
  <id>https://hackerone.com/reports/3913012</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3913012">Nextcloud: Persistent SMTP header injection via identity `organization` / `name`</a>]]></content>
</entry>

<entry>
  <title>curl: Socket API drops expired timeouts for transfers queued behind a connection limit</title>
  <link href="https://hackerone.com/reports/4021952" />
  <id>https://hackerone.com/reports/4021952</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/4021952">curl: Socket API drops expired timeouts for transfers queued behind a connection limit</a>]]></content>
</entry>

<entry>
  <title>[$150] Nextcloud: Group restriction bypass via bearer token in user_oidc (SETTING_RESTRICT_LOGIN_TO_GROUPS not enforced in Backend::getCurrentUserId)</title>
  <link href="https://hackerone.com/reports/3572848" />
  <id>https://hackerone.com/reports/3572848</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3572848">[$150] Nextcloud: Group restriction bypass via bearer token in user_oidc (SETTING_RESTRICT_LOGIN_TO_GROUPS not enforced in Backend::getCurrentUserId)</a>]]></content>
</entry>

<entry>
  <title>Essity: Unauthenticated API allows reading, writing to and deleting any user&#39;s private chat history on ████████</title>
  <link href="https://hackerone.com/reports/4020767" />
  <id>https://hackerone.com/reports/4020767</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/4020767">Essity: Unauthenticated API allows reading, writing to and deleting any user&#39;s private chat history on ████████</a>]]></content>
</entry>

<entry>
  <title>[$500] DuckDuckGo: SSRF with bypass leads to client side hosting / vulnerabilities ( XSS and others )</title>
  <link href="https://hackerone.com/reports/3522157" />
  <id>https://hackerone.com/reports/3522157</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3522157">[$500] DuckDuckGo: SSRF with bypass leads to client side hosting / vulnerabilities ( XSS and others )</a>]]></content>
</entry>

<entry>
  <title>Monero: sign_multisig crashes monero-wallet-rpc on a malformed but decryptable multisig txset</title>
  <link href="https://hackerone.com/reports/3683934" />
  <id>https://hackerone.com/reports/3683934</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3683934">Monero: sign_multisig crashes monero-wallet-rpc on a malformed but decryptable multisig txset</a>]]></content>
</entry>

<entry>
  <title>Monero: Restricted ZMQ RPC bypasses HTTP restricted-mode resource checks</title>
  <link href="https://hackerone.com/reports/3683886" />
  <id>https://hackerone.com/reports/3683886</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3683886">Monero: Restricted ZMQ RPC bypasses HTTP restricted-mode resource checks</a>]]></content>
</entry>

<entry>
  <title>Monero: ZMQ get_output_distribution duplicate amount DoS</title>
  <link href="https://hackerone.com/reports/3681690" />
  <id>https://hackerone.com/reports/3681690</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3681690">Monero: ZMQ get_output_distribution duplicate amount DoS</a>]]></content>
</entry>

<entry>
  <title>Nextcloud: Cross-User Lock/Unlock via Absolute DAV Path</title>
  <link href="https://hackerone.com/reports/3301553" />
  <id>https://hackerone.com/reports/3301553</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3301553">Nextcloud: Cross-User Lock/Unlock via Absolute DAV Path</a>]]></content>
</entry>

<entry>
  <title>Nextcloud: Shared smart albums in the Photos app can expose files outside the album owner&#39;s configured source folders</title>
  <link href="https://hackerone.com/reports/3506873" />
  <id>https://hackerone.com/reports/3506873</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3506873">Nextcloud: Shared smart albums in the Photos app can expose files outside the album owner&#39;s configured source folders</a>]]></content>
</entry>

<entry>
  <title>Nextcloud: Critical broken access control: API-only delegated admin can enumerate all Team Folders and grant access to arbitrary groups</title>
  <link href="https://hackerone.com/reports/3674940" />
  <id>https://hackerone.com/reports/3674940</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3674940">Nextcloud: Critical broken access control: API-only delegated admin can enumerate all Team Folders and grant access to arbitrary groups</a>]]></content>
</entry>

<entry>
  <title>Nextcloud: Public collectives allow to create pages</title>
  <link href="https://hackerone.com/reports/3533697" />
  <id>https://hackerone.com/reports/3533697</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3533697">Nextcloud: Public collectives allow to create pages</a>]]></content>
</entry>

<entry>
  <title>Nextcloud: Unauthenticated blind SSRF in Circles signature verification bypasses Nextcloud local-address protections</title>
  <link href="https://hackerone.com/reports/3303283" />
  <id>https://hackerone.com/reports/3303283</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3303283">Nextcloud: Unauthenticated blind SSRF in Circles signature verification bypasses Nextcloud local-address protections</a>]]></content>
</entry>

<entry>
  <title>[$200] Nextcloud: Team membership information returned on API level based on ID</title>
  <link href="https://hackerone.com/reports/3484601" />
  <id>https://hackerone.com/reports/3484601</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3484601">[$200] Nextcloud: Team membership information returned on API level based on ID</a>]]></content>
</entry>

<entry>
  <title>AWS VDP:  Incomplete Input Sanitization in CodeInterpreter install_packages Allows Command Injection via pip Flags</title>
  <link href="https://hackerone.com/reports/3633123" />
  <id>https://hackerone.com/reports/3633123</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3633123">AWS VDP:  Incomplete Input Sanitization in CodeInterpreter install_packages Allows Command Injection via pip Flags</a>]]></content>
</entry>

<entry>
  <title>Monero: Authenticated `unsigned_txset` change spoof lets a malicious hot wallet steal cold-signer change</title>
  <link href="https://hackerone.com/reports/3621588" />
  <id>https://hackerone.com/reports/3621588</id>
  <content type="html"><![CDATA[ <a href="https://hackerone.com/reports/3621588">Monero: Authenticated `unsigned_txset` change spoof lets a malicious hot wallet steal cold-signer change</a>]]></content>
</entry>

</feed>