Improper access control allows the attacker to comment on an internal commit after he's no longer an admin
HackerOne report #635512 by hx01 on 2019-07-04:
Description:
the attacker (previously maintainer) is able to comment in internal commits by replying to the notification email which were received before :
Steps to reproduce Setup:
- victim@domain.tld (maintainer)
- attacker@doamin.tld(maintainer)
PoC :
- the analyst should comment on their commit with victim@domain.tld --> attacker@doamin.tld will receive the notification.
- the analyst should remove the attacker@doamin.tld role after that
- the analyst should reply to the notification email received.:
- bingo! it will be posted to the commit :
Impact
this could be exploited to comment on the commits by the attacker who was accidentally added to the project or was removed .
Attachments
Warning: Attachments received through HackerOne, please exercise caution!
Edited by Heinrich Lee Yu

