IDOR in activateFuelCard id allows bulk lookup of driver uuids
Low
U
Uber
Submitted None
Team Summary
Official summary from Uber
Due to an IDOR in the `activateFuelCard` endpoint, an attacker could enumerate driver UUIDs. When given a sequential card ID number, the endpoint returned a driver’s UUID given, allowing an attacker to gather many driver UUIDs for use in a different attack. Thanks, @cablej!
Actions:
Reported by
cablej
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Direct Object Reference (IDOR)