url-redirect

1 article
sort: new top best
clear filter
0 5/10
bug-bounty

Elber Andre discovered SSRF vulnerabilities in Slack's slash commands and event subscriptions features by bypassing IPv6 protections using HTTP redirects with the [::] notation, earning $1,000 in total bounties ($500 per vulnerability).

Slack Elber Andre api.slack.com HackerOne CVE (referenced but not specific) agarri_fr slacka
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details