Starbucks Key API was suddenly revealed publicly on Github
Developers at Starbucks have made a serious mistake when publicly disclosing a key API that can be used by hackers to gain access to its internal systems, as well as manipulate user lists. Authorised.
The reason for this is extremely serious because this key can allow unlimited access to Starbucks JumpCloud API, as well as control Amazon Web Services (AWS) accounts, execute commands on the system. and add or remove accounts that have access to the internal system.
The entire incident was first discovered by Vinoth Kumar, when the free security researcher found Starbucks's API key in a GitHub repository that could be accessed publicly, and reported the details. detail the case through HackerOne's vulnerability coordination platform and reward bugs.
JumpCloud is an Active Directory management platform developed to replace Azure AD. The advantage of JumpCloud is to provide seamless and seamless user management, single sign-on access control (SSO) and Lightweight Directory Access (LDAP) service.
Vinoth Kumar reported the incident on October 17, and gave Starbucks three weeks to confirm the incident. After 3 weeks, information about the flaw will be publicly disclosed. Starbucks then analyzed and identified this as a serious flaw in the internal system, and said Vinoth Kumar was eligible to receive a $ 4,000 security bug detection bonus.
Starbucks has also been praised for its workaround when asking GitHub to delete the repository and revoke the exposed API key on October 21 - 4 days after the incident was reported. It took the company more time to issue an official press release because it needed to "ensure that the issue is understood and all appropriate corrective actions have been taken".
You should read it
- This is why users often do not want to pay for applications
- Debranding and the era of the 'no words' logo
- Top 10 beautiful cafes in Cau Giay area, delicious drinks, tired hands photographed
- What does leak mean?
- How to check and fix DNS leak error in VPN
- Detected the archive containing data of thousands of Zoom accounts on the dark web forum
- How to fix Windows 10 memory leak
- How to fix memory leaks on Android
- Microsoft releases tool to help detect memory leaks with Edge
- VPN vulnerabilities and how to check and prevent them
- What is WebRTC Leak? How to prevent?
- Microsoft's 6 Biggest Hacks