Arbitrary pipeline execution GraphQL (Re)DoS Leaky role permissions SAML OAuth / OIDC Maven dependency proxy HTML injection Codeowners bypass Sensitive data exposure Merge request bypass Package registry CSRF / SSRF Privilege escalation Banned users not actually banned Improper token revocation AI Emojis CI/CD scheduling ../ CI/CD variable exposure User impersonation Pages domain hijack Authn bypass Arbitrary pipeline execution GraphQL (Re)DoS Leaky role permissions SAML OAuth / OIDC Maven dependency proxy HTML injection Codeowners bypass Sensitive data exposure Merge request bypass Package registry CSRF / SSRF Privilege escalation Banned users not actually banned Improper token revocation AI Emojis CI/CD scheduling ../ CI/CD variable exposure User impersonation Pages domain hijack Authn bypass
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
Arbitrary pipeline execution
GraphQL
(Re)DoS
Leaky role permissions
SAML
OAuth / OIDC
Maven dependency proxy
HTML injection
Codeowners bypass
Sensitive data exposure
Merge request bypass
Package registry
CSRF / SSRF
Privilege escalation
Banned users not actually banned
Improper token revocation
AI
Emojis
CI/CD scheduling
../
CI/CD variable exposure
User impersonation
Pages domain hijack
Authn bypass