Github - Profile Email Address not Validated

Profile email address not validated

Observed that users could save an arbitrary email address to their profile. This could have allowed an attacker to perform a social engineering attack by adding an email address to their profile that belonged to another user. When a user adds a collaborator to a repository they can find them by their username or their profile email address. As a result, by registering an email address of another user, an attacker may have been able to confuse the repository owner and have caused them to add the attacker’s account as a collaborator. We remediated this issue by requiring a verified email address for future updates to a user’s profile email address.

Donated bounty to The Tor Project

  • Github Bug Bounty Page: Profile email address not validated