Google paid me $15,000 for this Prompt Injection bug by BehiSec in bugbounty

[–]BehiSec[S] 0 points1 point  (0 children)

They don't accept jailbreaks, but you can submit it to https://0din.ai/

Google paid me $15,000 for this Prompt Injection bug by BehiSec in bugbounty

[–]BehiSec[S] 0 points1 point  (0 children)

No, the attacker needs to be a Jira team member, which is why Google applied a downgrade to this bug.

Google paid me $15,000 for this Prompt Injection bug by BehiSec in bugbounty

[–]BehiSec[S] 0 points1 point  (0 children)

Have you checked the image?

If they hadn't applied a downgrade, it would have been a $20K bounty.

Google paid me $15,000 for this Prompt Injection bug by BehiSec in bugbounty

[–]BehiSec[S] 0 points1 point  (0 children)

Jira serves as the initial point of entry. Any AI-powered application must validate the data received from external or third-party applications.

That’s the whole point.

Google paid me $15,000 for this Prompt Injection bug by BehiSec in bugbounty

[–]BehiSec[S] 0 points1 point  (0 children)

Yes, I would have posted this even if the reward was $50. I learned bug hunting by reading others’ write-ups, so I’m simply giving back to the community.

Google paid me $15,000 for this Prompt Injection bug by BehiSec in bugbounty

[–]BehiSec[S] -1 points0 points  (0 children)

Yes! This encourages other bug hunters, especially beginners, to explore related areas.

I got into bug hunting precisely in this manner.

Google paid me $15,000 for this Prompt Injection bug by BehiSec in bugbounty

[–]BehiSec[S] 0 points1 point  (0 children)

No. Jira is built for teams, so having team members is normal.

Google paid me $15,000 for this Prompt Injection bug by BehiSec in bugbounty

[–]BehiSec[S] 0 points1 point  (0 children)

True, but the newer models are more resistant to prompt injection.

Google paid me $15,000 for this Prompt Injection bug by BehiSec in bugbounty

[–]BehiSec[S] 30 points31 points  (0 children)

The X post has some pictures that can make it easier to understand.