Personal Access Token Disclosure in Asana Desktop Application
This post gives an insight into a sensitive data exposure vulnerability in Asana for Mac that was rated as P1 and was awarded a bounty.
This was the very first report of that kind for me. Still, I think this type of deployment and build chain issue is more common than one may think.
Flickr Account Takeover
This post gives a deep dive into a critical security flaw that was present in Flickr’s login flow.
The authentication at identity.flickr.com is implemented using AWS Cognito. By exploiting configuration issues and violations of the OpenID Connect specification, it was possible to takeover any Flickr account without user interaction.
TikTok Careers Portal Account Takeover
The following (slightly modified) vulnerability report was sent to TikTok using Hackerone on 17th October 2020 and was resolved within 12 days.
CVE-2020-13294
The following (slightly modified) advisory was sent to GitLab using Hackerone on 19th June 2020.
macOS Catalina: PostScript evaluation to Remote Denial-of-Service
The following (slightly modified) advisory regarding macOS 10.15.6. (Catalina) was sent to Apple Product Security on 25th August 2020.
CVE-2019-11832
The following (slightly modified) advisory was sent to the TYPO3 security team (security@typo3.org) on 28th January 2019.