Access Grab_Road BigData Database via Open Presto coordinator
Critical
G
Grab
Submitted None
Team Summary
Official summary from Grab
A publicly accessible analytics database instance was identified, due to a firewall misconfiguration. The instance contained booking related information but did not contained any passenger or driver personal information. This vulnerability was discovered using Shodan search engine by **Vinoth Kumar**. Grab security team quickly resolved the issue and awarded the researcher based on the impact. Once again we would like to thanks @vinothkumar. It was a pleasure to work with and we look forward to see more of his reports in the future.
Actions:
Reported by
vinothkumar
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$5000.00
Submitted
Weakness
Information Disclosure