![]() |
|
HackerOne Disclosed Reports - 2025-11-03 - Printable Version +- Dark C0d3rs (https://darkcoders.wiki) +-- Forum: Exploit Log (https://darkcoders.wiki/Forum-Exploit-Log) +--- Forum: Research Papers/Vulnerability reports (https://darkcoders.wiki/Forum-Research-Papers-Vulnerability-reports) +--- Thread: HackerOne Disclosed Reports - 2025-11-03 (/Thread-HackerOne-Disclosed-Reports-2025-11-03) |
HackerOne disclosed reports - 2025-11-03 - hashXploiter - 11-04-2025
Medium
resolved Microsoft `x-apikey` Exposed in Mozilla CI Public LogsBug reported by Omar was disclosed at November 3, 2025, 10:34 am | Cleartext Storage of Sensitive Information A Microsoft telemetry API key (x-apikey) was found exposed in publicly accessible Mozilla CI logs. The key appeared in HTTP POST requests sent to Microsoft's telemetry endpoint during automated Firefox testing and was captured via mitmproxy logs. The security impact was considered minimal as the telemetry API key had limited functionality. The report was accepted and a bonus was paid as recognition of the reporter's efforts. |