█.8x8.vc/index.js: Exposed Google Maps API Key Allowing Potential Abuse of Paid Services
Medium
8
8x8 Bounty
Submitted None
Team Summary
Official summary from 8x8 Bounty
We resolved an issue where a Google Maps API key allowed potential unauthorized access to some Google Maps services. While the API key was intentionally included in client-side code, it lacked proper restrictions to prevent abuse of paid services. The potential impact could theoretically lead to API quota consumption and related billing concerns, though actual impact was limited as no evidence of exploitation was found. Our team promptly validated and addressed the report by implementing appropriate API key restrictions where feasible, while accepting other known limitations.
Actions:
Reported by
abdallasamir12
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$500.00
Submitted
Weakness
Information Disclosure