Slack token leaking in stackoverflow and devtimes
Medium
S
Shipt
Submitted None
Team Summary
Official summary from Shipt
A Shipt employee inadvertently posted a Slack Webhook URI including the authentication token on two public tech forums: Stackoverflow.com and devtimes.com. While this incoming webhook's configuration was restricted to posting in a single channel (created for testing this application) and only 2 Shipt users were in this channel, this allowed the researcher to enumerate those 2 users and post unauthorized messages as the bot associated with the Webhook. Upon receiving the report, Shipt 's security team immediately invalidated the Webhook.
Actions:
Reported by
streaak
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$300.00
Submitted
Weakness
Cleartext Storage of Sensitive Information