cookie-security

1 article
Sort: New Top Best
clear filter
0 9/10

A multi-stage vulnerability in GitHub's private pages authentication flow combining CRLF injection, null byte parsing bypass, and cookie prefix case-sensitivity to achieve XSS and cache poisoning on private organization pages. The attack exploited case-insensitive cookie handling to bypass __Host- prefix protections and nonce fixation to achieve unauthenticated arbitrary code execution.

GitHub HackerOne ginkoid $35,000 bounty github.io pages-auth.github.com
robertchen.cc · kh4sh3i/bug-bounty-writeups · 4 hours ago · details