Closed
Bug 1364769
Opened 9 years ago
Closed 9 years ago
Categories
(Websites :: Other, defect)
Websites
Other
Tracking
(Not tracked)
RESOLVED
WONTFIX
People
(Reporter: vladimirmetnew, Unassigned)
References
()
Details
(Keywords: reporter-external, Whiteboard: [reporter-external] [web-bounty-form])
DB is accessible at https://api-mozillascience-staging.herokuapp.com/users/ and https://api-mozillascience-production.herokuapp.com/users/ . Attacker has access to emails/social networks profiles/names/etc of users, including Mozilla developers.
(DB stores many profiles with @mozilla emails)
Other routes from this app https://github.com/mozilla/api.mozillascience.org/ are accessible for attacker too. (~1000 users)
Flags: sec-bounty?
| Reporter | ||
Updated•9 years ago
|
Summary: Full DB exposure at https://api-mozillascience-production.herokuapp.com/users/ → DB at https://api-mozillascience-production.herokuapp.com/users/
Thanks vladimirmetnew!
+gideon: is this data supposed to be public?
Status: UNCONFIRMED → NEW
Ever confirmed: true
Flags: needinfo?(gideon)
Whiteboard: [reporter-external] [web-bounty-form] [verif?] → [reporter-external] [web-bounty-form]
| Reporter | ||
Comment 2•9 years ago
|
||
Personally, I can't find page in this app(I mean frontend app) that returns users list or just user info. But API(backend) is open.
Comment 3•9 years ago
|
||
I'll find out from a stakeholder but iirc it was meant to be on a user page on science.mozilla.org but is yet to be implemented
Comment 4•9 years ago
|
||
Confirmed, the user data is actually populated from Github so this data is already public
Flags: needinfo?(gideon)
Thanks Gideon.
Vladimir, thanks again for your report. I'm going to close this, but let us know if you find other resources that shouldn't be public.
Group: websites-security
Status: NEW → RESOLVED
Closed: 9 years ago
Resolution: --- → WONTFIX
Updated•9 years ago
|
Flags: sec-bounty? → sec-bounty-
Updated•2 years ago
|
Keywords: reporter-external
You need to log in
before you can comment on or make changes to this bug.
Description
•