Full account takeover of any user through reset password U.S. Dept Of Defense disclosed a bug submitted by maskedpersian: https://hackerone.com/reports/2194928 [Source]
XSS in Cisco Endpoint U.S. Dept Of Defense disclosed a bug submitted by r00tdaddy: https://hackerone.com/reports/2233421 [Source]
Unathenticated file read (CVE-2020-3452) U.S. Dept Of Defense disclosed a bug submitted by r00tdaddy: https://hackerone.com/reports/2233418 [Source]