In-app reader
Serious question for other bug bounty researchers. I reported the same underlying security issue twice. Bugcrowd marked both filings duplicate. Except they were duplicated against two different original reports . I asked them to reconcile which original actually constituted prior art. I did not ask to see the private reports or for any confidential researcher information. The response I received was basically: same code change/fix = duplicate. But that still doesn’t explain how the same issue ended up attributed to two different originals. And “same fix” doesn’t necessarily prove “same vulnerability.” One patch can fix multiple security problems. I’m intentionally not posting technical details because this came from a private program. My criticism is strictly about the triage logic: If the same vulnerability is assigned to two different originals, shouldn’t Bugcrowd internally determine which one actually establishes the duplicate? Curious how other researchers would view this. submitted by /u/Other-Butterfly9927 [link] [comments]
Discussion
Sign in to join the discussion.
Keep reading
Optional: create a free account to save items, track programs, and sync across web + app. Reading stays free.