The popular web code development and hosting platform, GitHub, recently launched a bug bounty program, motivating several researchers to search for errors in the platform's code repositories.
One of these researchers is Egor Homakov, who managed to gain access to private GitHub repositories using a combination of 5 low-severity flaws.
Individually, these flaws cannot be exploited to cause significant damage, but when combined, a high-severity vulnerability results.
The researcher notified GitHub about the vulnerability, which was promptly patched
Homakov was awarded $4,000 (€2,935), the largest reward offered by GitHub to date.
Additional technical details are available on Homakov's blog and Reddit.
📧
Subscribe to the SecNews Newsletter

