
4/3/2019
What this post added
This post announces that Shopify has awarded over $1M USD in bug bounties through its programs on HackerOne. It provides statistics on the program's performance (over 400+ hackers, 950+ bugs resolved, 750+ bounties awarded, 375+ public disclosures) and details three significant vulnerabilities: SSRF in Exchange leading to ROOT access ($25K bounty), an authentication bypass using partners.shopify.com ($20K bounty), and stored XSS in the admin and partner pages ($5K bounty). The post also mentions ongoing efforts to enhance the program's competitiveness and attractiveness to researchers.