User impersonation HTML injection Codeowners bypass Merge request bypass Maven dependency proxy CSRF / SSRF CI/CD variable exposure Privilege escalation GraphQL Banned users not actually banned ../ Authn bypass AI Package registry SAML Leaky role permissions OAuth / OIDC Pages domain hijack Arbitrary pipeline execution Improper token revocation Emojis CI/CD scheduling Sensitive data exposure (Re)DoS User impersonation HTML injection Codeowners bypass Merge request bypass Maven dependency proxy CSRF / SSRF CI/CD variable exposure Privilege escalation GraphQL Banned users not actually banned ../ Authn bypass AI Package registry SAML Leaky role permissions OAuth / OIDC Pages domain hijack Arbitrary pipeline execution Improper token revocation Emojis CI/CD scheduling Sensitive data exposure (Re)DoS
(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.
User impersonation
HTML injection
Codeowners bypass
Merge request bypass
Maven dependency proxy
CSRF / SSRF
CI/CD variable exposure
Privilege escalation
GraphQL
Banned users not actually banned
../
Authn bypass
AI
Package registry
SAML
Leaky role permissions
OAuth / OIDC
Pages domain hijack
Arbitrary pipeline execution
Improper token revocation
Emojis
CI/CD scheduling
Sensitive data exposure
(Re)DoS