![]() |
|
HackerOne Disclosed Reports - 2025-04-08 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2025-04-08 (/Thread-HackerOne-Disclosed-Reports-2025-04-08) |
HackerOne disclosed reports - 2025-04-08 - hashXploiter - 04-09-2025
Medium
resolved (Part 2) Non-Production API Endpoints for the Datazone Service Fail to Log to CloudTrail Resulting in Silent Permission EnumerationBug reported by Nick Frichette (Datadog) was disclosed at April 8, 2025, 4:14 pm | Insufficient Logging The non-production API endpoints for the Datazone service failed to log to CloudTrail, resulting in silent permission enumeration. The vulnerability was discovered through certificate transparency monitoring, where three additional vulnerable endpoints were identified. |