OAuth / OIDC Leaky role permissions Emojis CSRF / SSRF Codeowners bypass Privilege escalation Authn bypass Improper token revocation Merge request bypass HTML injection CI/CD scheduling Sensitive data exposure AI GraphQL Package registry CI/CD variable exposure Arbitrary pipeline execution Pages domain hijack Banned users not actually banned Maven dependency proxy ../ User impersonation SAML (Re)DoS OAuth / OIDC Leaky role permissions Emojis CSRF / SSRF Codeowners bypass Privilege escalation Authn bypass Improper token revocation Merge request bypass HTML injection CI/CD scheduling Sensitive data exposure AI GraphQL Package registry CI/CD variable exposure Arbitrary pipeline execution Pages domain hijack Banned users not actually banned Maven dependency proxy ../ User impersonation SAML (Re)DoS
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
OAuth / OIDC
Leaky role permissions
Emojis
CSRF / SSRF
Codeowners bypass
Privilege escalation
Authn bypass
Improper token revocation
Merge request bypass
HTML injection
CI/CD scheduling
Sensitive data exposure
AI
GraphQL
Package registry
CI/CD variable exposure
Arbitrary pipeline execution
Pages domain hijack
Banned users not actually banned
Maven dependency proxy
../
User impersonation
SAML
(Re)DoS