Skip to main content  >
Hackerone logo
Hacktivity
Opportunities
Directory
Leaderboard
Learn more about HackerOne
Log in
#2598548
Bypassing HackerOne 2FA due to race condition
  • Share:
Summary by HackerOne
A race condition vulnerability was identified in HackerOne's 2FA reset process. The issue allowed an attacker to initiate multiple parallel 2FA reset requests, resulting in multiple reset notification emails. When a user canceled one reset request, the remaining requests would stay active, potentially leading to unauthorized 2FA removal after 24 hours.
Timeline
akashhamal0x01
ID-verifiedHacker that has successfully completed an ID verification check.
akashhamal0x01
submitted a report to HackerOne.
July 12, 2024, 9:25am UTC
Show older activities
akashhamal0x01
 posted a comment. 
Updated October 30, 2024, 2:32pm UTC
akashhamal0x01
 posted a comment. 
Updated July 12, 2024, 9:25pm UTC
akashhamal0x01
 posted a comment. 
July 18, 2024, 2:47am UTC
h1_analyst_aaron
HackerOne triage
 changed the status to
Pending program review
. 
July 23, 2024, 9:45am UTC
hendrik_hv01h
HackerOne staff
 updated the severity to
medium (4.8)
. 
July 25, 2024, 11:29am UTC
hendrik_hv01h
HackerOne staff
 changed the status to Triaged. 
July 25, 2024, 11:31am UTC
hendrik_hv01h
HackerOne staff
 posted a comment. 
July 25, 2024, 11:34am UTC
akashhamal0x01
 posted a comment. 
July 25, 2024, 12:30pm UTC
akashhamal0x01
 posted a comment. 
July 31, 2024, 12:59pm UTC
h1_analyst_aaron
HackerOne triage
 posted a comment. 
August 1, 2024, 6:28am UTC
HackerOne
 rewarded akashhamal0x01 with a bounty. 
August 2, 2024, 8:55am UTC
h1_chriszo111
HackerOne staff
 changed the status to Retesting. 
Updated October 29, 2024, 4:32pm UTC
Akash Hamal
ID-verifiedHacker that has successfully completed an ID verification check.
akashhamal0x01
 completed a retest. 
Updated October 30, 2024, 2:32pm UTC
akashhamal0x01
 posted a comment. 
October 29, 2024, 8:29pm UTC
h1_chriszo111
HackerOne staff
 changed the report title. 
October 30, 2024, 2:19pm UTC
HackerOne
 accepted completed retest from the retester. 
October 30, 2024, 2:21pm UTC
h1_chriszo111
HackerOne staff
 closed the report and changed the status to Resolved. 
October 30, 2024, 2:21pm UTC
akashhamal0x01
 posted a comment. 
October 30, 2024, 2:23pm UTC
h1_chriszo111
HackerOne staff
 requested to disclose this report. 
October 30, 2024, 2:48pm UTC
akashhamal0x01
 agreed to disclose this report. 
October 30, 2024, 2:56pm UTC
 This report has been disclosed. 
October 30, 2024, 2:56pm UTC
akashhamal0x01
 posted a comment. 
October 31, 2024, 10:34am UTC
akashhamal0x01
 posted a comment. 
December 14, 2024, 7:24am UTC
wvdv
HackerOne staff
 posted a comment. 
December 16, 2024, 2:16pm UTC
akashhamal0x01
 posted a comment. 
February 23, 2025, 9:58am UTC
Reported on
July 12, 2024, 9:25am UTC
Reported by
akashhamal0x01
akashhamal0x01
Reported to
HackerOne
Managed
Participants
akashhamal0x01
wvdv
h1_chriszo111
zahra_h1
h1_analyst_aaron
hendrik_hv01h
Report Id
#2598548
Resolved
Severity
Medium (4.8)

Disclosed
October 30, 2024, 2:56pm UTC
Weakness
Business Logic Errors
CVE ID
None

Bounty
Hidden 

Account details
None