Despite fixing the issue, Zendesk ultimately chose not to award a bounty for my report. Their reasoning? I had broken HackerOne’s disclosure guidelines by sharing the vulnerability with affected companies
Regardless of everything else they should be kicked out from HackerOne since it’s clearly Zendesk not being truthful here.
It’s because it isn’t true. We don’t go looking unless it’s needed.