Security Hall of Fame

Valid, previously-unknown reports under our bug bounty program. Summaries are published after a fix; we do not disclose tokens, personal data or exploit steps.

Bug bounty program — scope, rules and rewards

Anupam Giri

  • Highdjangoeurope message queue

    Cross-tenant RabbitMQ credential attachment

    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H = 7.5, High

    CWE-639 · CWE-862 — CWE-639 (Authorization Bypass Through User-Controlled Key / IDOR). CWE-862 (Missing Authorization) is the missing ownership check on the vhost.

    POST /rabbitmquser/ did not check that the caller owned the vhost named in the request body, so any authenticated account could attach a credential of its own choosing to any vhost whose UUID it knew.

    Confirmed, and accepted at High. We take the reporter’s word on the AMQPS step and did not need to re-run it. We debated Medium internally, on the grounds that an attacker needs a vhost UUID and the report does not demonstrate a way to obtain one. That second point is fair, and we checked it ourselves rather than assume: the id of the RabbitMQ instance is a UUID4 id. A UUID4 is 122 bits of random space, so guessing or enumerating one is impractical, and taking over another customer’s RabbitMQ account this way is very hard. The one broadly readable RabbitMQ endpoint exposes clusters without their vhosts, so we found no disclosure path either.

  • In reviewwcenter / djangoeurope payments

    Bank-transfer payment reference taken from the URL

    CWE-639 · CWE-472 — CWE-639 (Authorization Bypass Through User-Controlled Key / IDOR). CWE-472 (External Control of Assumed-Immutable Web Parameter) covers taking CID and reference from the URL.

    Reported that the bank-transfer page showed CID and payment reference from the URL query string, with no check that those values belong to the logged-in account. A crafted link could instruct a customer to put someone else’s reference on a real wire transfer. Card and PayPal top-up on the same page were not affected.

    Not yet fixed. In review.

Pramod Kumar Ravela

IndiaLinkedInBugcrowd

  • Mediumwcenter / djangoeurope

    Password reset token not invalidated after use

    CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N = 6.8, Medium — top of the band, just under High.

    CWE-640 · CWE-613 — CWE-640 (Weak Password Recovery Mechanism for Forgotten Password). CWE-613 (Insufficient Session Expiration) covers the token remaining valid after a successful change.

    Reported that a password reset token was not invalidated after a successful password change, allowing a reset link to be replayed for the remainder of its two-hour lifetime.

    Reset tokens are now strictly single-use. The report also prompted a wider review of our password reset flow, which led us to enforce our password policy on that path, sign out existing browser sessions on reset, invalidate superseded reset links, and add rate limiting to the endpoint. Our thanks for a clearly written and reproducible report.

Gaurang Maheta

  • Mediumdjangoeurope registration, password reset, trial accounts and contact form

    Client-side-only registration anti-bot check

    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N = 5.3, Medium

    CWE-602 · CWE-804 — CWE-602 (Client-Side Enforcement of Server-Side Security). CWE-804 (Guessable CAPTCHA) is the more precise fit and is cited alongside it.

    The registration anti-spam check could be computed entirely in the client — no server secret, nonce or expiry — so it did not stop automated account creation.

    Accepted in full. Registration, password reset, trial-account creation and the contact form now require a server-issued proof-of-work challenge bound to the request: signed and scoped by our own infrastructure, with an expiry, single-use, and not forgeable offline. We use self-hosted proof-of-work rather than a third-party CAPTCHA, so there is no extra processor, cookie or fingerprinting. Proof-of-work is not a hard barrier; rate limits remain the main ceiling on abuse. The old client-side gate is being removed in a staged change once this has been stable. Our thanks for a clean, correct report that got a long-standing issue fixed.

  • Mediumdjangoeurope registration & password reset

    Missing rate limits on registration and password reset

    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N = 6.4

    CWE-770 · CWE-799 — CWE-770 (Allocation of Resources Without Limits or Throttling). CWE-799 (Improper Control of Interaction Frequency) is the frequency-control view of the same gap.

    Login is throttled, but registration and password-reset were not. Registration could create accounts and send welcome mail without a cap; password reset sent mail on every request, so one inbox could be flooded.

    Accepted at Medium. The reported vector is unchanged. The harm is mail volume and sending reputation, which CVSS models poorly because the impact falls on a third party’s inbox rather than on our own system; that does not change the rating. The fix is deployed. Registration cannot bomb a single address — one welcome mail per address — but could send to many distinct addresses; password reset could flood one inbox. Both endpoints now have rate limits, including a per-target cap on reset mail so rotating IPs against one inbox no longer works. Reset tokens remain strictly single-use, independently of those limits. Our thanks for a clear and reproducible report; it prompted us to review the whole unauthenticated surface around registration and password reset.

  • Mediumdjangoeurope registration

    Unauthenticated customer-email enumeration

    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N = 5.3

    CWE-204 — CWE-204 (Observable Response Discrepancy).

    The registration endpoint returned different error messages for already-registered versus unknown email addresses, so an unauthenticated caller could confirm which addresses were customers.

    The oracle is closed. Anonymous registration now answers the same way whether the address is new or already a customer; a duplicate creates nothing. The address owner may receive a notice that an account already exists, linking to the password-reset page with no reset token. Our thanks for reporting this alongside the rate-limit finding.

Want to be listed? Report a finding through the bug bounty program.