Loading HuntDB...

Getting all the CD keys of any game

Critical
V
Valve
Submitted None

Team Summary

Official summary from Valve

Using the `/partnercdkeys/assignkeys/` endpoint on partner.steamgames.com with specific parameters, an authenticated user could download previously-generated CD keys for a game which they would not normally have access. Audit logs were not bypassed using this method, and an investigation of those audit logs did not show any prior or ongoing exploitation of this bug.

Reported by moskowsky

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$20000.00

Submitted

Weakness

Improper Access Control - Generic