Loading HuntDB...

Improper authorization allows disclosing users' notification data in Notification channel server

High
L
LY Corporation
Submitted None

Team Summary

Official summary from LY Corporation

LINE Channel authentication provides separate authentication tokens for each LINE Channel. Due to the bug in the authentication process in the Notifications Channel service, it could be possible for an attacker to get the Notifications Channel data of another user by using their valid authentication token from another channel, for example, if an attacker creates their own channel and makes victim account to join it.

Reported by aki__0421

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$2000.00

Submitted

Weakness

Improper Authorization