Root cause
An error-handling configuration could include unintended application data in a response; subsequent review found a broader framework issue.
Demonstrated impact
A copyright-management request could return data fragments not intended for the requester. The award reflected the vendor’s assessment of potential wider impact.
Lessons for review
- Apply data-minimization rules to error responses as well as successful responses.
- Review shared exception-handling behavior after an endpoint-level fix.
Award and evidence
Vendor explicitly identifies USD and says the report was paid. Exact transfer date is unknown; this is not the event or program total.
Read the official vendor retrospective and its explicit US-dollar per-report payment. Summaries retain the vendor’s bounded impact statement.
- Historical case; exact award, settlement and deployment dates are unknown.
- The source gives a high-level finding, not a complete technical advisory.
Recorded timeline
- Published
- 2020-02-07explicit · Initial page date; a separate May 7, 2020 update is displayed.
- Reported
- 2019-09inferred · September event in the vendor’s 2019 retrospective; the day is unspecified.
Sources and provenance
- 2019 Bug Bounty highlights, official Spanish edition Dan Gurfinkel / Facebook · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.