Security News > 2020 > March > Slack Vulnerability Allowed Hackers to Hijack Accounts

Slack Vulnerability Allowed Hackers to Hijack Accounts
2020-03-16 15:14

A researcher earned $6,500 from Slack last year after finding a critical vulnerability that could have been exploited to hijack Slack accounts.

The vulnerability was reported to Slack in mid-November via the company's bug bounty program on HackerOne and it was patched within 24 hours, which is not uncommon for Slack when it comes to account hijacking issues.

The vendor provided the following description for the vulnerability: This researcher exploited an HTTP Request Smuggling bug on a Slack asset to perform a CL.TE-based hijack onto neighboring customer requests.

This hijack forced the victim into an open-redirect that forwarded the victim onto the researcher's collaborator client with slack domain cookies.

Slack typically offers $1,500 for critical vulnerabilities found in its products.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/-WIHAE5KBrs/slack-vulnerability-allowed-hackers-hijack-accounts