Brute Force Attack against PIN on Card History Page Could Lead to Card Information Discovery / Fraud
None
S
Starbucks
Submitted None
Team Summary
Official summary from Starbucks
@kylecolson demonstrated the ability to brute force Starbucks Card numbers at a specific endpoint, then worked with our team to answer questions and verify the fix. Rate-limiting issues have been identified as an item listed as an exclusion within our program and have therefore been considered out of scope. However, this particular finding helped to identify an inconsistency in controls already applied. As a result, we will be evaluating how we triage and determine rate-limiting issues for eligibility in the future. Thanks @kylecolson!
Actions:
Reported by
kylecolson
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Violation of Secure Design Principles