Information Disclosure FrontPage Configuration Information U.S. Dept Of Defense disclosed a bug submitted by gu4rdianbyte: https://hackerone.com/reports/2180018 [Source]
After the upload of an private file, using transformations, the file becomes public without the possibility of changing it. Mozilla Critical Services disclosed a bug submitted by limusec: https://hackerone.com/reports/1984060 - Bounty: $1000 [Source]
HTML Injection at https://stage.firefoxmonitor.nonprod.cloudops.mozgcp.net/user/unsubscribe Mozilla Core Services disclosed a bug submitted by avram: https://hackerone.com/reports/1913263 [Source]