ABCDEFGHIJK
1
#AuthorTitleLinkSIV AllocationPublic AllocationTotalDiffRelative Diff
2
2cjackettWeak RNG in Auth Token Generationhttps://github.com/siv-org/siv/issues/178$634.92$498.44$1,133.36-$136.4824%
3
4mspecter"I will pay $1 for your vote"https://github.com/siv-org/siv/issues/181$113.38$744.29$857.67$630.91147%
4
42aaspring2nd Device Malware Verification Check could be fooled by rerouting the QR code to another malicious sitehttps://github.com/siv-org/siv/issues/231$566.89$284.93$851.82-$281.9666%
5
31anon-person404The Frontend & Backend is Open to Supply Chain Attackshttps://github.com/siv-org/siv/issues/204$340.14$285.78$625.92-$54.3617%
6
11mspecterSIV webapp could maliciously steal Observer's private keyhttps://github.com/siv-org/siv/issues/197$272.11$164.29$436.40-$107.8249%
7
18mspecterRisks associated with Firebase dependencyhttps://github.com/siv-org/siv/issues/197$340.14$91.45$431.59-$248.69115%
8
16mspecterUnclear defense against malicious clientshttps://github.com/siv-org/siv/issues/197$226.76$157.43$384.19-$69.3336%
9
6anonrisk of border gateway protocol attacks?https://github.com/siv-org/siv/issues/191$272.11$82.88$354.99-$189.23107%
10
33anon-person404Chrome Client Compromise & Vote Manipulationhttps://github.com/siv-org/siv/issues/221$68.03$250.65$318.68$182.62115%
11
25GABurasEmail disinformationhttps://github.com/siv-org/siv/issues/197$113.38$187.21$300.59$73.8349%
12
17mspecterVulnerability to email delivery manipulation by Mailgunhttps://github.com/siv-org/siv/issues/197$113.38$178.60$291.98$65.2245%
13
41GABurasPreparing for missing encryption receiptshttps://github.com/siv-org/siv/issues/189$68.03$218.44$286.47$150.41105%
14
1cjackettLack of Input Validation and Sanitization in Admin Login Endpointhttps://github.com/siv-org/siv/issues/177$136.05$145.74$281.79$9.697%
15
9mspecterLack of formal threat modelhttps://github.com/siv-org/siv/issues/197$113.38$159.31$272.69$45.9334%
16
23mspecterVulnerable to chosen hosting servicehttps://github.com/siv-org/siv/issues/197$158.73$83.60$242.33-$75.1362%
17
40GABurasDuplicate Verification Numbershttps://github.com/siv-org/siv/issues/189$22.68$197.92$220.60$175.24159%
18
13mspecterToo thin docs for voter remediation procedureshttps://github.com/siv-org/siv/issues/197$158.73$47.27$206.00-$111.46108%
19
15mspecterMissing Merkle tree implementationhttps://github.com/siv-org/siv/issues/197$158.73$27.17$185.90-$131.56142%
20
24GABurasVerification went to spamhttps://github.com/siv-org/siv/issues/196$68.03$107.53$175.56$39.5045%
21
19mspecterSecurity concerns with Google Tag Managerhttps://github.com/siv-org/siv/issues/197$113.38$60.31$173.69-$53.0761%
22
12mspecterMalicious observers could block decryptionhttps://github.com/siv-org/siv/issues/197$113.38$57.86$171.24-$55.5265%
23
22mspecterVulnerability to malicious pushover?https://github.com/siv-org/siv/issues/197$113.38$57.29$170.67-$56.0966%
24
30cjackettShorten JWT Expiration Time for Improved Session Managementhttps://github.com/siv-org/siv/issues/203$90.70$64.42$155.12-$26.2834%
25
29cjackettExplicitly Set JWT Signing Algorithm to Ensure Securityhttps://github.com/siv-org/siv/issues/202$22.68$127.58$150.26$104.90140%
26
37pleasework-shSame email can be verified twicehttps://github.com/siv-org/siv/issues/189$68.03$72.86$140.89$4.837%
27
14mspecterRisk of false claims of ballot discrepancieshttps://github.com/siv-org/siv/issues/197$113.38$9.57$122.95-$103.81169%
28
34pmeyersonVoter Extortionhttps://github.com/siv-org/siv/issues/223$90.70$32.14$122.84-$58.5695%
29
7cjackettUnrestricted CORS Policy Vulnerabilityhttps://github.com/siv-org/siv/issues/193$22.68$88.57$111.25$65.89118%
30
32cjackettPotential Denial of Service (DoS) Vulnerability Due to High Volume of Requestshttps://github.com/siv-org/siv/issues/205$0.00$107.29$107.29$107.29200%
31
26Automatic476No Security.md file for tracking versions within the repohttps://github.com/siv-org/siv/issues/198$45.35$60.17$105.52$14.8228%
32
5mspecterdocs: coercion resistance !== receipt-freenesshttps://github.com/siv-org/siv/issues/190$45.35$60.00$105.35$14.6528%
33
27Automatic476Vulnerabilites Found Based on Questionshttps://github.com/siv-org/siv/issues/199$68.03$32.86$100.89-$35.1770%
34
39pleasework-shVotes can be submitted with the same ciphertextshttps://github.com/siv-org/siv/issues/189$22.68$67.14$89.82$44.4699%
35
28cjackettAvoid Logging JWT Contents to Prevent Sensitive Data Exposurehttps://github.com/siv-org/siv/issues/201$22.68$57.14$79.82$34.4686%
36
10mspecterUnclear role and security of observershttps://github.com/siv-org/siv/issues/197$45.35$8.17$53.52-$37.18139%
37
8cjackettMove Sensitive Environment Variables to a Secret Management Servicehttps://github.com/siv-org/siv/issues/194$0.00$52.14$52.14$52.14200%
38
20mspecterPusher as a single point of failure for observer communicationhttps://github.com/siv-org/siv/issues/197$22.68$24.57$47.25$1.898%
39
21mspecterVulnerability to malicious supabase?https://github.com/siv-org/siv/issues/197$22.68$18.14$40.82-$4.5422%
40
38
worldpeaceworker
lack of did support and human verification systemhttps://github.com/siv-org/siv/issues/189$11.34$2.57$13.91-$8.77126%
41
36pleasework-shUsers may mistype email address for verificationhttps://github.com/siv-org/siv/issues/189$0.00$11.43$11.43$11.43200%
42
35pmeyersonSystem Integrity Proof?https://github.com/siv-org/siv/issues/224$0.00$7.57$7.57$7.57200%
43
3phishProposed custom-verification-text eases(?) vote sellinghttps://github.com/siv-org/siv/issues/115#issuecomment-2273475134$0.00$7.29$7.29$7.29200%
44