Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

馃毃 Potential Improper Access Control #175

Open
huntr-helper opened this issue May 18, 2021 · 11 comments
Open

馃毃 Potential Improper Access Control #175

huntr-helper opened this issue May 18, 2021 · 11 comments

Comments

@huntr-helper
Copy link

馃憢 Hello, @athas - a potential high severity Improper Access Control vulnerability in your repository has been disclosed to us.

Next Steps

1锔忊儯 Visit https://huntr.dev/bounties/1-other-athas/EggsML for more advisory information.

2锔忊儯 Sign-up to validate or speak to the researcher for more assistance.

3锔忊儯 Propose a patch or outsource it to our community - whoever fixes it gets paid.


Confused or need more help?

  • Join us on our Discord and a member of our team will be happy to help! 馃

  • Speak to a member of our team: @JamieSlome


This issue was automatically generated by huntr.dev - a bug bounty board for securing open source code.

@Sword-Smith
Copy link
Collaborator

@huntr-helper Do you guys accept payment in Bitcoin Lightning?

@JamieSlome
Copy link

@adam-nygate - bump 馃憡

@JamieSlome
Copy link

JamieSlome commented Aug 25, 2021

@Sword-Smith - thanks for the question!

We do not accept Bitcoin Lightning, but we can accept standard Bitcoin.

Would this work for you?

@Sword-Smith
Copy link
Collaborator

A regular Bitcoin transaction would work since the fees are low at the moment.

@JamieSlome
Copy link

@Sword-Smith - feel free to use our public BTC address 3Jcm5VE6DpDHaxLZJC1ZAiPPTfU4aSaNqJ.

Cheers! 馃帀

@Sword-Smith
Copy link
Collaborator

So what do I send to this address? 10 USD to have the issue revealed, and 5 USD to set a bounty to fix it?

@JamieSlome
Copy link

Ah sorry for the confusion. No payment is required to access the report. We give access to the maintainer(s) of the repository either via magic-link or once they've logged in to the platform.

We welcome the sponsoring of reports/fixes via multiple payment methods.

@Sword-Smith
Copy link
Collaborator

Sword-Smith commented Aug 25, 2021

No problem. Sent you 15 USD anyway in ee592e86b72109ecf09da62d5729f3f3312a227d029d57241898ac3a0b9af659
https://blockstream.info/tx/ee592e86b72109ecf09da62d5729f3f3312a227d029d57241898ac3a0b9af659

@sshine
Copy link
Collaborator

sshine commented Feb 3, 2022

@JamieSlome:

  • Is it possible for other team members of EggsML to access this report?
  • I see that you have previously received credit for a CWE-471 vulnerability (Modification of Assumed-Immutable Data (MAID)); I am very sure that the concieggs sub-project qualifies as MAID. How do we escalate this so that we can credit you further?
  • Do you still accept Bitcoin payments?

@sshine sshine added this to the FOR L脝NGST! milestone Feb 3, 2022
@sshine sshine self-assigned this Feb 3, 2022
@JamieSlome
Copy link

JamieSlome commented Feb 3, 2022

@sshine:

  • Yes, absolutely, I will just need to get a magic URL for you to share with different team members.
  • When you say escalate, do you mean to assign a CVE? We can assign CVEs if you would like to do this and believe the report to be valid.
  • We do still accept Bitcoin donations, but just for clarity, we by default sponsor all bounties to help secure OSS 鉂わ笍 Happy to share an address if you would like to donate!

Let me know how you want to proceed with the report, and will make sure you get access! 馃帀

@JamieSlome
Copy link

Just a heads up that our BTC address is:

32K3SmVHVgsWjYGDyjfa8ryGYG7Fx3qLpv

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants