Google Docs link in JS files allows editing & reading survey information

Program: hackerone Bug Type: Information disclosure Bounty: 2500 Date: 2023-09-25
information-disclosure data-leak lack-of-permissions

Summary

The researcher who was monitoring Javascript files of hackerone found a new update that introduced a variable with a google docs link. The google docs link was leaked via the file https://hackerone.com/assets/static/js/5930.078b8e86.chunk.js, The document was editable and had global read permission.

References