Starbucks China Android app cloud storage service leaks a credential.
High
S
Starbucks
Submitted None
Team Summary
Official summary from Starbucks
k3mlol found a credential encoded in the Starbucks China mobile application for Android phones, which provided access to a cloud-hosted service that was used to upload information for customer service requests. This credential allowed for read/write access. The credential has since been disabled, and replacement credentials in newer versions of the application are managed differently to avoid their exposure and to restrict access to write-only. Thank you @k3mlol for submitting a valuable report and your continued assistance as we worked through to the final resolution.
Actions:
Reported by
k3mlol
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure