Improper authorization allows disclosing users' notification data in Notification channel server
High
L
LY Corporation
Submitted None
Team Summary
Official summary from LY Corporation
LINE Channel authentication provides separate authentication tokens for each LINE Channel. Due to the bug in the authentication process in the Notifications Channel service, it could be possible for an attacker to get the Notifications Channel data of another user by using their valid authentication token from another channel, for example, if an attacker creates their own channel and makes victim account to join it.
Actions:
Reported by
aki__0421
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$2000.00
Submitted
Weakness
Improper Authorization