Vulnerabilities tagged "bounty"

Editing a User to Add Sensitive Scopes to a JWT

Had a JWT, and noticed functionality to invite a user to a group and then change their privileges, these privileges were reflected in the JWT scopes.Though modification of this edit user request additional scopes that were not displayed could be added, such as the `company:operations` and `company:support` scopes...
 

Three Apple CloudKit Vulnerabilities

Three bugs relating to insecurely configured CloudKit containers, the big one being the accidental deletion of all Apple Shortcuts, but also the ability to delete records on Apple News, and modify data used on the iCrowd+ website.
 
3
4
5
6
7
8
9