back to article Slack whacks global account hijack holes

Hipster collaboration platform Slack has shuttered an access control bypass that allowed users to hijack any account. The flaws reported by security researcher David Viera-Kurz lay in twin path traversal and access control bypasses. Slack paid Viera-Kurz US$9000 for privately reporting two flaws under its bug bounty program …

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like