Race condition in performing retest allows duplicated payments
Program: hackerone
Bug Type: Race condition
Bounty: 2500
Date: 2018-10-26
race-condition
Summary
The researcher found a race condition vulnerability in the retest feature of bounty reporting in hackerone, when you submit a report and gets triaged, the Triage team can ask you for retest, and a retest is paid a specific amount. The researcher found out that by concurrently sending the retest request multiple times, multiple payments are made from hackerone.