Privacy policy contains hardcoded link using unencrypted HTTP
Low
U
Uber
Submitted None
Team Summary
Official summary from Uber
The link to Uber’s privacy policy was using the unencrypted `http://` scheme, making it possible for an attacker with the ability to Man-in-The-Middle (MiTM) traffic. This would allow them to replace normal responses with malicious content such as a phishing page. The content would then render within the Uber application, making for a credible phishing attack.
Actions:
Reported by
nightwatch-cybersecurity
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Code Injection