Closed Bug 1364769 Opened 9 years ago Closed 9 years ago

Categories

(Websites :: Other, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED WONTFIX

People

(Reporter: vladimirmetnew, Unassigned)

References

()

Details

(Keywords: reporter-external, Whiteboard: [reporter-external] [web-bounty-form])

DB is accessible at https://api-mozillascience-staging.herokuapp.com/users/ and https://api-mozillascience-production.herokuapp.com/users/ . Attacker has access to emails/social networks profiles/names/etc of users, including Mozilla developers. (DB stores many profiles with @mozilla emails) Other routes from this app https://github.com/mozilla/api.mozillascience.org/ are accessible for attacker too. (~1000 users)
Flags: sec-bounty?
Summary: Full DB exposure at https://api-mozillascience-production.herokuapp.com/users/ → DB at https://api-mozillascience-production.herokuapp.com/users/
Thanks vladimirmetnew! +gideon: is this data supposed to be public?
Status: UNCONFIRMED → NEW
Ever confirmed: true
Flags: needinfo?(gideon)
Whiteboard: [reporter-external] [web-bounty-form] [verif?] → [reporter-external] [web-bounty-form]
Personally, I can't find page in this app(I mean frontend app) that returns users list or just user info. But API(backend) is open.
I'll find out from a stakeholder but iirc it was meant to be on a user page on science.mozilla.org but is yet to be implemented
Confirmed, the user data is actually populated from Github so this data is already public
Flags: needinfo?(gideon)
Thanks Gideon. Vladimir, thanks again for your report. I'm going to close this, but let us know if you find other resources that shouldn't be public.
Group: websites-security
Status: NEW → RESOLVED
Closed: 9 years ago
Resolution: --- → WONTFIX
Flags: sec-bounty? → sec-bounty-
You need to log in before you can comment on or make changes to this bug.