Signature verification bypass from slack allows unlimited operations

Disclosed by
shiki
  • Engagement Atlassian-Built Apps
  • Disclosed date almost 2 years ago
  • Reward $900
  • Priority P2 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by Atlassian-Built Apps

Authentication Bypass - Signature verification bypass in Slack integration allows restricted operations.

Summary by shiki

Signature verification bypass from slack allows unlimited operations on slack integration.

Activity