Getting all the CD keys of any game
Critical
V
Valve
Submitted None
Team Summary
Official summary from Valve
Using the `/partnercdkeys/assignkeys/` endpoint on partner.steamgames.com with specific parameters, an authenticated user could download previously-generated CD keys for a game which they would not normally have access. Audit logs were not bypassed using this method, and an investigation of those audit logs did not show any prior or ongoing exploitation of this bug.
Actions:
Reported by
moskowsky
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$20000.00
Submitted
Weakness
Improper Access Control - Generic