Bungie-net / api

Resources for the Bungie.net API
Other
1.22k stars 92 forks source link

Security issue #1921

Closed EricCacciavillani closed 2 months ago

EricCacciavillani commented 2 months ago

I have no idea if I am allowed to write here or wether or not my tired mind is completely wrong but I am worried I found a security bug with the Bungie.net system and would love to dm someone about this....I dont want to put this in a public setting as it could be harmful to people.

EricCacciavillani commented 2 months ago

Again truly sorry if I am not allowed to write here. I mean no ill will towards anyone. I do think I have something that malicious users could use...please let me know if anyone gets a second. (And again I mean no ill will....this is fully accidental that I figured this out in sleep deprivation....)

leanderson-bng commented 2 months ago

Hi @EricCacciavillani, you can use HackerOne to report a vulnerability. Details can be found here: https://secure.sony.com/