logo

You Received A Vulnerability Report, Now What? 6 Steps to Resolution

ID: 8c80cb0b-89de-54d0-a262-1fef2ed06e3a

STIX ID: report--8c80cb0b-89de-54d0-a262-1fef2ed06e3a

Feed Name: HackerOne Blog

Threat Score
45/100

Date Published: 2023-09-07

Date Updated: 2026-06-11

...
...

HackerOne recounts an incident in which a researcher discovered an Amazon S3 bucket misconfiguration permitting writes by any authenticated AWS user; follow-up root cause analysis revealed additional writable buckets and one readable (but encrypted) bucket. The post describes the remediation (overhaul of S3 permissions), a higher bounty paid after finding further issues, and prescribes security playbook practices—performing root cause analysis, reviewing code, validating fixes, logging/forensics, and working with external researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.