Just got a reward for a vulnerability submitted on @yeswehack -- Cross-site Scripting (XSS) - Reflected (CWE-79). https://t.co/SFKMZBkHba #YesWeRHackers
@h4x0r_dz@intigriti Yes, it was airflow web app then you need to access to admin airflow then you can read user,pass for jenkins in anothet port then get rce from jenkins then you need get root using python script with rwx permissions
Just scored a reward 1875€ @intigriti#HackWithIntigriti#bugbountytips
Tip: I played ctf this year and i found this vulnerability because i solve machine challenge with same bug
If you found apache airflow use flask-unsign to found secret key and generate new jwt for admin