Race condition in performing retest allows duplicated payments

Program: hackerone Bug Type: Race condition Bounty: 2500 Date: 2018-10-26
race-condition

Summary

The researcher found a race condition vulnerability in the retest feature of bounty reporting in hackerone, when you submit a report and gets triaged, the Triage team can ask you for retest, and a retest is paid a specific amount. The researcher found out that by concurrently sending the retest request multiple times, multiple payments are made from hackerone.

References