Authn bypass Leaky role permissions Sensitive data exposure Codeowners bypass AI Merge request bypass (Re)DoS Pages domain hijack Improper token revocation Arbitrary pipeline execution CI/CD variable exposure Privilege escalation User impersonation CI/CD scheduling Emojis SAML GraphQL Banned users not actually banned ../ Package registry Maven dependency proxy CSRF / SSRF OAuth / OIDC HTML injection Authn bypass Leaky role permissions Sensitive data exposure Codeowners bypass AI Merge request bypass (Re)DoS Pages domain hijack Improper token revocation Arbitrary pipeline execution CI/CD variable exposure Privilege escalation User impersonation CI/CD scheduling Emojis SAML GraphQL Banned users not actually banned ../ Package registry Maven dependency proxy CSRF / SSRF OAuth / OIDC HTML injection
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
Authn bypass
Leaky role permissions
Sensitive data exposure
Codeowners bypass
AI
Merge request bypass
(Re)DoS
Pages domain hijack
Improper token revocation
Arbitrary pipeline execution
CI/CD variable exposure
Privilege escalation
User impersonation
CI/CD scheduling
Emojis
SAML
GraphQL
Banned users not actually banned
../
Package registry
Maven dependency proxy
CSRF / SSRF
OAuth / OIDC
HTML injection