Starbucks Key API was suddenly revealed publicly on Github
Developers at Starbucks have made a serious mistake when publicly disclosing a key API that can be used by hackers to gain access to its internal systems, as well as manipulate user lists. Authorised.
The reason for this is extremely serious because this key can allow unlimited access to Starbucks JumpCloud API, as well as control Amazon Web Services (AWS) accounts, execute commands on the system. and add or remove accounts that have access to the internal system.
The entire incident was first discovered by Vinoth Kumar, when the free security researcher found Starbucks's API key in a GitHub repository that could be accessed publicly, and reported the details. detail the case through HackerOne's vulnerability coordination platform and reward bugs.
JumpCloud is an Active Directory management platform developed to replace Azure AD. The advantage of JumpCloud is to provide seamless and seamless user management, single sign-on access control (SSO) and Lightweight Directory Access (LDAP) service.
Vinoth Kumar reported the incident on October 17, and gave Starbucks three weeks to confirm the incident. After 3 weeks, information about the flaw will be publicly disclosed. Starbucks then analyzed and identified this as a serious flaw in the internal system, and said Vinoth Kumar was eligible to receive a $ 4,000 security bug detection bonus.
Starbucks has also been praised for its workaround when asking GitHub to delete the repository and revoke the exposed API key on October 21 - 4 days after the incident was reported. It took the company more time to issue an official press release because it needed to "ensure that the issue is understood and all appropriate corrective actions have been taken".
You should read it
- Top 10 beautiful cafes in Cau Giay area, delicious drinks, tired hands photographed
- What does leak mean?
- How to check and fix DNS leak error in VPN
- Detected the archive containing data of thousands of Zoom accounts on the dark web forum
- How to fix Windows 10 memory leak
- How to fix memory leaks on Android
- Microsoft releases tool to help detect memory leaks with Edge
- VPN vulnerabilities and how to check and prevent them
May be interested
- How to Import a Repository on Githubgithub's personal repositories are essentially storage spaces for project files. you can import a repository on github by using an old project url and the github importer; you can also use the command line to import old repositories. open...
- Google Launches Gemini CLI GitHub Actions: Automate PR Review, Issue Triage, and Moregoogle has just announced gemini cli github actions - a completely free ai programming support tool, developed from internal needs in managing pull requests and issues on github.
- Is GitHub Copilot or ChatGPT better for programming?github copilot and chatgpt are two of the most popular ai programming support tools available. they use the same gpt large language model and are capable of generating, recommending, and testing code. so which one should you use?
- Microsoft is about to buy GitHubis simply love?
- GitHub Models launches, allowing developers to find and test AI models for freegithub has officially announced github models, a new service that allows developers to find and test ai models for free.
- How to Download a GitHub Folderthis wikihow teaches you how to download a github folder by downloading an entire repository. github allows you to download a repo locally to your computer with just a few simple steps. please note that downloading a specific folder from...
- 82% of code on GitHub is copying existing filesthat's the result of a recent study by researchers from the university of california, irvine, microsoft research, czech technical and northeastern.
- GitHub is under strong phishing attack, users pay attention to account securitygithub - the world's largest open source software repository, is now the target of a phishing attack campaign.
- GitHub Copilot is now available for free in VS Codegithub, the most popular platform for the global developer community, has officially surpassed 150 million members.
- GitHub's machine learning tool can detect vulnerabilities in codegithub's tool will help eliminate common security holes before the code is put into the final stage.