{"id":28159,"date":"2025-01-20T22:10:57","date_gmt":"2025-01-20T16:40:57","guid":{"rendered":"https:\/\/blogrevamp.cashfree.com\/?p=28159"},"modified":"2025-01-21T12:58:45","modified_gmt":"2025-01-21T07:28:45","slug":"routine-security-test-for-bug-bounty-discovery","status":"publish","type":"post","link":"https:\/\/blogrevamp.cashfree.com\/routine-security-test-for-bug-bounty-discovery\/","title":{"rendered":"How a Routine Security Test Led to My First CVE and Bug Bounty: Lessons in API Security and Beyond"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_81 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #005c31;color:#005c31\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #005c31;color:#005c31\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/blogrevamp.cashfree.com\/routine-security-test-for-bug-bounty-discovery\/#The_Not_So_Routine_Security_Task\" >The Not So Routine Security Task<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/blogrevamp.cashfree.com\/routine-security-test-for-bug-bounty-discovery\/#Discovering_a_Third-Party_Tool\" >Discovering a Third-Party Tool<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/blogrevamp.cashfree.com\/routine-security-test-for-bug-bounty-discovery\/#The_Testing_Process\" >The Testing Process<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/blogrevamp.cashfree.com\/routine-security-test-for-bug-bounty-discovery\/#The_unexpected_vulnerability\" >The unexpected vulnerability<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/blogrevamp.cashfree.com\/routine-security-test-for-bug-bounty-discovery\/#Reporting_and_Realisation\" >Reporting and Realisation<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/blogrevamp.cashfree.com\/routine-security-test-for-bug-bounty-discovery\/#The_Lightbulb_Moment\" >The Lightbulb Moment<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/blogrevamp.cashfree.com\/routine-security-test-for-bug-bounty-discovery\/#Key_Learnings\" >Key Learnings<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/blogrevamp.cashfree.com\/routine-security-test-for-bug-bounty-discovery\/#Conclusion\" >Conclusion<\/a><\/li><\/ul><\/nav><\/div>\n\n<p class=\"wp-block-paragraph\">Every security engineer has that one story\u2014<strong><em>an unexpected discovery <\/em><\/strong>that changes the course of their career. For me, that moment came when I stumbled upon a serious vulnerability in a tool we were using.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What started as a pretty routine security test turned out to be a journey for earning my very first<a href=\"https:\/\/docs.retool.com\/disclosures\/cve-2024-42056\"> <strong>CVE ID<\/strong><\/a>, my first <strong>Bug Bounty<\/strong>, and discovering the intricacies of API security.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this engineering blog, we share the key lessons and insights from that experience, focusing on the importance of vigilance in security testing and beyond. So, let\u2019s get started.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Not_So_Routine_Security_Task\"><\/span><strong>The Not So Routine Security Task<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It began as what seemed like just another security test. Our fintech product was set to launch in a few short weeks, and it was important to ensure that everything was secure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As part of our routine process, we run multiple security tests on all our applications before they are sent to production. I approached this assessment as any other, starting by focusing on the potential authorisation issues in the APIs.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Discovering_a_Third-Party_Tool\"><\/span><strong>Discovering a Third-Party Tool<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As I began my testing, I soon realised that this new product was built on top of a third-party tool called<a href=\"https:\/\/retool.com\/\"> <strong>Retool<\/strong><\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Retool makes it easy to build internal apps, such as admin panels and dashboards, on top of your data sources.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Testing_Process\"><\/span><strong>The Testing Process<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For this testing, I had three distinct roles based on different user privileges:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Admin: For Administrator Controls and Tasks<\/li>\n\n\n\n<li>Requester: For Requesting the Resource<\/li>\n\n\n\n<li>Approver: For Approving\/Rejecting the Requester\u2019s Request<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The authorisation for this application was handled by<a href=\"https:\/\/jwt.io\/introduction\"> <strong>JWT tokens<\/strong><\/a>, which is a well-known practice for securing APIs and handling authentication and authorisation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">My goal was quite straightforward: <strong>&#8220;<\/strong>Can the admin APIs be accessed by other roles?<strong>\u201d<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I set up a proxy tool and explored the application by logging in as the admin and capturing all the admin-related API calls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Interestingly, one of those calls,&nbsp;named &#8220;<strong>\/api\/resources<\/strong>,<strong>&#8220;<\/strong> fetched access resources for the user.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After logging out, I logged in again as &#8220;<strong>Requester<\/strong>.&#8221; As the admin-related API(s) was already captured by the proxy tool, I took the <strong>\/api\/resources<\/strong> Admin API(s) request, replaced the admin JWT token with the requester\u2019s token, and sent the request.<\/p>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\"><img fetchpriority=\"high\" decoding=\"async\" width=\"624\" height=\"335\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXf3LyluP1eZtyXYLVZjk4roBr1dY0W4lRyq5u2t6okhSvfsqoZDYsfpr9zKzRrUJjTHEt5eRz0Dji78bRsgsn4yofNVj8mjI9MNxxN5-_7Cei843jFQF89nj-ugc3-jIum8dZL4LA?key=EoVwDgyJzkSD188ZoGdnL3F6\"><br><em>Burp Repeater showing response for \u201c\/api\/response\u201d token<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_unexpected_vulnerability\"><\/span><strong>The unexpected vulnerability<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">To my surprise, the server-side response was identical. This meant that admin APIs were accessible to a regular user\u2014an unequivocal case of <strong>&#8216;Broken Access Control.&#8217;<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Taking a closer look at the response, the bell continued to ring even louder: the response was leaking a database username and password.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This was not just a case of broken access control, where data was exposed to a larger audience than intended, but also a case of sensitive data exposure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first lesson learned: <strong>\u201c<\/strong>Never blindly trust that a third-party tool\u2019s security is flawless. Your product\u2019s security is still your responsibility.\u201d<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Reporting_and_Realisation\"><\/span><strong>Reporting and Realisation<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">I quickly reported the issue to our developers, only to find out that the problem was rooted in Retool.<\/p>\n\n\n\n<p class=\"has-text-align-left wp-block-paragraph\">We immediately brought it up to Retool\u2019s team, and to their credit, they acted swiftly. Just a few days later, they released a security advisory to all its users, including us.<\/p>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\"><img decoding=\"async\" width=\"374\" height=\"524\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXeUFDqk40M-3ouih5zueFIukRq5cd2fwp75DtQ3RXSApgALP_vZX3Ehm42ewrE9u3tNP38Cwt06j95i_SLRQTpC-6TsEB2naQlBkyyzNzbbz390Aeho9CCo-RJP18-B1L2VVkTFWw?key=EoVwDgyJzkSD188ZoGdnL3F6\"><br><em>Security advisory email from Retool<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Lightbulb_Moment\"><\/span><strong>The Lightbulb Moment<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When the security advisory hit my inbox, my eyes opened wide. I realised how seriously the situation could go\u2014<strong>this was no local issue at all with our product.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It was a global vulnerability that could potentially affect many users. That\u2019s when I took a call to take things forward.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I reached out to Retool, sent a request for credit of discovery, and requested a bug bounty along with a CVE ID.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This time, Retool was helpful too. In just a matter of a few days, the<a href=\"https:\/\/docs.retool.com\/disclosures\/cve-2024-42056\"> &#8220;<strong>CVE-2024-42056&#8243;<\/strong><\/a> was issued to my name along with a bug bounty.<\/p>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\"><img decoding=\"async\" width=\"624\" height=\"336\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXfom1lnXYrD5judQ0mdP40a6v-aS_3rP3IL2Pu8N7JR4J-v4zcIeLm0R_RnbhZynTqUYlU2uMs5QTuDwRuXHUxTa5yAxrdZfqxXYa_6EV3VjxZvkwMsINzKsYb192-0BAWNHEvpWw?key=EoVwDgyJzkSD188ZoGdnL3F6\"><br><em>CVE ID acknowledgment<\/em><\/p>\n\n\n\n<p class=\"has-text-align-center wp-block-paragraph\"><img loading=\"lazy\" decoding=\"async\" width=\"624\" height=\"351\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXcnyZMDa5dmo9Zs0BfKa4eHintuQJvydANEP1CoPYrDPtZhSwJ9vmbOtoAdNnLJolAuQW-r-z-vwN6-7bdNShs-ipdK2WH7xFM0YzxXfgp7EJvSgIUsPhlfc-PCEddWpkdoPTpx2g?key=EoVwDgyJzkSD188ZoGdnL3F6\"><br><em>My First Bug Bounty Earning\u00a0<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Key_Learnings\"><\/span><strong>Key Learnings<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This experience reinforced some valuable lessons about API security and the need for vigilance:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Never Blindly Trust Third-Party Tools:<\/strong> Just because a tool is used often doesn\u2019t mean that it is immune to flaws in terms of security. Always run your own security tests on third-party tools as well.<\/li>\n\n\n\n<li><strong>Broken Access Control: <\/strong>Always test for broken access controls, especially when you are using an application with multiple user roles. Ensure no user has access to data or functionality beyond the designated role.<\/li>\n\n\n\n<li><strong>Too Much Data Exposure: <\/strong>Know what your APIs expose. Sensitive information such as database credentials. should never appear in API responses, regardless of the user&#8217;s role.<\/li>\n\n\n\n<li><strong>Always Ask for Credit:<\/strong> If you find something big, do not be afraid to ask credit for it. This could have just been another report, but I took it beyond that and made it a career milestone for me.<\/li>\n\n\n\n<li><strong>Stay Curious and Persistent:<\/strong> What started as routine testing led to a significant discovery because I didn\u2019t stop at the surface. Always dig deeper and explore every possible angle.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Conclusion\"><\/span><strong>Conclusion<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In the field of cybersecurity, even the most routine tasks can lead to extraordinary outcomes. This experience has not only marked my first CVE ID and bug bounty but also reinforced the importance of thorough security testing, especially when dealing with APIs and third-party tools.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Every security engineer has that one story\u2014an unexpected discovery that changes the course of their career. For me, that moment came when I stumbled upon a serious vulnerability in a tool we were using. What started as a pretty routine security test turned out to be a journey for earning my very first CVE ID,<\/p>\n","protected":false},"author":110,"featured_media":28161,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"_themeisle_gutenberg_block_has_review":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[1497],"tags":[],"class_list":["post-28159","post","type-post","status-publish","format-standard","has-post-thumbnail","category-engineering"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How a Routine Security Test Led to CVE &amp; Bug Bounty Discovery<\/title>\n<meta name=\"description\" content=\"Learn how routine API security tests uncovered a critical vulnerability, earning CVE ID and bug bounty. Learn key lessons in API security, third-party risks, and persistence.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cashfree.com\/blog\/routine-security-test-for-bug-bounty-discovery\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How a Routine Security Test Led to CVE &amp; Bug Bounty Discovery\" \/>\n<meta property=\"og:description\" content=\"Learn how routine API security tests uncovered a critical vulnerability, earning CVE ID and bug bounty. Learn key lessons in API security, third-party risks, and persistence.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cashfree.com\/blog\/routine-security-test-for-bug-bounty-discovery\/\" \/>\n<meta property=\"og:site_name\" content=\"Cashfree Payments Blog\" \/>\n<meta property=\"article:published_time\" content=\"2025-01-20T16:40:57+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-01-21T07:28:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/i0.wp.com\/blogrevamp.cashfree.com\/wp-content\/uploads\/2025\/01\/Anubhavs-Blog-_-Lessons-in-API-Security-and-Beyond_Main-Tn.png?fit=1249%2C818&ssl=1\" \/>\n\t<meta property=\"og:image:width\" content=\"1249\" \/>\n\t<meta property=\"og:image:height\" content=\"818\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"anubhav sharma\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"anubhav sharma\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How a Routine Security Test Led to CVE & Bug Bounty Discovery","description":"Learn how routine API security tests uncovered a critical vulnerability, earning CVE ID and bug bounty. Learn key lessons in API security, third-party risks, and persistence.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cashfree.com\/blog\/routine-security-test-for-bug-bounty-discovery\/","og_locale":"en_US","og_type":"article","og_title":"How a Routine Security Test Led to CVE & Bug Bounty Discovery","og_description":"Learn how routine API security tests uncovered a critical vulnerability, earning CVE ID and bug bounty. Learn key lessons in API security, third-party risks, and persistence.","og_url":"https:\/\/www.cashfree.com\/blog\/routine-security-test-for-bug-bounty-discovery\/","og_site_name":"Cashfree Payments Blog","article_published_time":"2025-01-20T16:40:57+00:00","article_modified_time":"2025-01-21T07:28:45+00:00","og_image":[{"width":1249,"height":818,"url":"https:\/\/i0.wp.com\/blogrevamp.cashfree.com\/wp-content\/uploads\/2025\/01\/Anubhavs-Blog-_-Lessons-in-API-Security-and-Beyond_Main-Tn.png?fit=1249%2C818&ssl=1","type":"image\/png"}],"author":"anubhav sharma","twitter_card":"summary_large_image","twitter_misc":{"Written by":"anubhav sharma","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cashfree.com\/blog\/routine-security-test-for-bug-bounty-discovery\/#article","isPartOf":{"@id":"https:\/\/blogrevamp.cashfree.com\/routine-security-test-for-bug-bounty-discovery\/"},"author":{"name":"anubhav sharma","@id":"https:\/\/blogrevamp.cashfree.com\/#\/schema\/person\/e8a177192a154a5bb7910f6a6205054a"},"headline":"How a Routine Security Test Led to My First CVE and Bug Bounty: Lessons in API Security and Beyond","datePublished":"2025-01-20T16:40:57+00:00","dateModified":"2025-01-21T07:28:45+00:00","mainEntityOfPage":{"@id":"https:\/\/blogrevamp.cashfree.com\/routine-security-test-for-bug-bounty-discovery\/"},"wordCount":903,"commentCount":0,"image":{"@id":"https:\/\/www.cashfree.com\/blog\/routine-security-test-for-bug-bounty-discovery\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/blogrevamp.cashfree.com\/wp-content\/uploads\/2025\/01\/Anubhavs-Blog-_-Lessons-in-API-Security-and-Beyond_Main-Tn.png?fit=1249%2C818&ssl=1","articleSection":["Engineering"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.cashfree.com\/blog\/routine-security-test-for-bug-bounty-discovery\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/blogrevamp.cashfree.com\/routine-security-test-for-bug-bounty-discovery\/","url":"https:\/\/www.cashfree.com\/blog\/routine-security-test-for-bug-bounty-discovery\/","name":"How a Routine Security Test Led to CVE & Bug Bounty Discovery","isPartOf":{"@id":"https:\/\/blogrevamp.cashfree.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cashfree.com\/blog\/routine-security-test-for-bug-bounty-discovery\/#primaryimage"},"image":{"@id":"https:\/\/www.cashfree.com\/blog\/routine-security-test-for-bug-bounty-discovery\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/blogrevamp.cashfree.com\/wp-content\/uploads\/2025\/01\/Anubhavs-Blog-_-Lessons-in-API-Security-and-Beyond_Main-Tn.png?fit=1249%2C818&ssl=1","datePublished":"2025-01-20T16:40:57+00:00","dateModified":"2025-01-21T07:28:45+00:00","author":{"@id":"https:\/\/blogrevamp.cashfree.com\/#\/schema\/person\/e8a177192a154a5bb7910f6a6205054a"},"description":"Learn how routine API security tests uncovered a critical vulnerability, earning CVE ID and bug bounty. Learn key lessons in API security, third-party risks, and persistence.","breadcrumb":{"@id":"https:\/\/www.cashfree.com\/blog\/routine-security-test-for-bug-bounty-discovery\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cashfree.com\/blog\/routine-security-test-for-bug-bounty-discovery\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cashfree.com\/blog\/routine-security-test-for-bug-bounty-discovery\/#primaryimage","url":"https:\/\/i0.wp.com\/blogrevamp.cashfree.com\/wp-content\/uploads\/2025\/01\/Anubhavs-Blog-_-Lessons-in-API-Security-and-Beyond_Main-Tn.png?fit=1249%2C818&ssl=1","contentUrl":"https:\/\/i0.wp.com\/blogrevamp.cashfree.com\/wp-content\/uploads\/2025\/01\/Anubhavs-Blog-_-Lessons-in-API-Security-and-Beyond_Main-Tn.png?fit=1249%2C818&ssl=1","width":1249,"height":818,"caption":"API Security"},{"@type":"BreadcrumbList","@id":"https:\/\/www.cashfree.com\/blog\/routine-security-test-for-bug-bounty-discovery\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blogrevamp.cashfree.com\/"},{"@type":"ListItem","position":2,"name":"Engineering","item":"https:\/\/blogrevamp.cashfree.com\/category\/engineering\/"},{"@type":"ListItem","position":3,"name":"How a Routine Security Test Led to My First CVE and Bug Bounty: Lessons in API Security and Beyond"}]},{"@type":"WebSite","@id":"https:\/\/blogrevamp.cashfree.com\/#website","url":"https:\/\/blogrevamp.cashfree.com\/","name":"Cashfree Payments Blog","description":"Cashfree Payments- Payment Gateway for India","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blogrevamp.cashfree.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blogrevamp.cashfree.com\/#\/schema\/person\/e8a177192a154a5bb7910f6a6205054a","name":"anubhav sharma","url":"https:\/\/blogrevamp.cashfree.com\/author\/anubhavsharma92\/"}]}},"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9MjXo-7kb","jetpack_likes_enabled":false,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/blogrevamp.cashfree.com\/wp-content\/uploads\/2025\/01\/Anubhavs-Blog-_-Lessons-in-API-Security-and-Beyond_Main-Tn.png?fit=1249%2C818&ssl=1","_links":{"self":[{"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/posts\/28159","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/users\/110"}],"replies":[{"embeddable":true,"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/comments?post=28159"}],"version-history":[{"count":9,"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/posts\/28159\/revisions"}],"predecessor-version":[{"id":28194,"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/posts\/28159\/revisions\/28194"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/media\/28161"}],"wp:attachment":[{"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/media?parent=28159"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/categories?post=28159"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/tags?post=28159"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}