Loading HuntDB...

Starbucks China Android app cloud storage service leaks a credential.

High
S
Starbucks
Submitted None

Team Summary

Official summary from Starbucks

k3mlol found a credential encoded in the Starbucks China mobile application for Android phones, which provided access to a cloud-hosted service that was used to upload information for customer service requests. This credential allowed for read/write access. The credential has since been disabled, and replacement credentials in newer versions of the application are managed differently to avoid their exposure and to restrict access to write-only. Thank you @k3mlol for submitting a valuable report and your continued assistance as we worked through to the final resolution.

Reported by k3mlol

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure