The U.S. Department of Defense (DoD) has disclosed details about four vulnerabilities found in its infrastructure. Two of these vulnerabilities have been rated “high severity,” while the other two have been rated “critical.” The vulnerabilities, which were first disclosed in July and August, could allow hackers to take over a subdomain, execute arbitrary code remotely, or view files on the affected computer. All of the issues were reported through the Department’s vulnerability disclosure on the HackerOne bug bounty by prominent ethical hackers.
One of the critical vulnerabilities is a subdomain takeover , due to an untrusted Amazon S3 bucket. Ethical hacker chron0x , who found the issue, said that this could be exploited to host malicious content on a legitimate domain . The site's visitors would then be subject to phishing and cross-site scripting attacks. The flaw would also allow an attacker to bypass domain security and steal sensitive user data

The second vulnerability, rated critical, was reported by Hzllaga on August 19. It is a remote code execution vulnerability on server running Apache Solr that has not been patched since August 2019. The server was vulnerable to the vulnerabilities identified as CVE-2019-0192 and CVE-2019-0193, but only the latter was enough for an attacker to obtain a shell on the server. However, both are exploitable.
Another vulnerability stemming from unpatched software, discovered by IT security analyst Dan (a veteran of the U.S. Navy and Coast Guard), is a read-only path traversal that could allow an attacker to gain access to sensitive and confidential system files. This is a vulnerability found in a Cisco product .

The second, less serious vulnerability is a injection code into a DoD server that could lead to arbitrary code execution, according to the report by e3xpl0it, a penetration tester at cybersecurity firm Positive Technologies.
In all cases, the U.S. Department of Defense promptly fixed the issues. According to statistics from the HackerOne platform, it took the Department about eight hours, on average, to fix and address each of the vulnerabilities. Since the U.S. Department of Defense began its vulnerability disclosure program on HackerOne in November 2016, it has addressed 9,555 security issues. Notably, the Department has addressed more than a third of these in the past three months.
