User Information sent to client through websockets
I
Instacart
Submitted None
Actions:
Reported by
archers123
Vulnerability Details
Technical details and impact analysis
I noticed when monitoring the websocket requests that the account information of user, including user_id is sent to the client.
__{"t":"d","d":{"r":8,"a":"p","b":{"p":"/carts/3671079_xjdJHqx88J435eDW5zxN/users/-KRbGN8R6uIjy6_OPx_j","d":{"id":25390626,"name":"Username}}}}__
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Information Disclosure