Google Maps API key leaked during device pairing
Team Summary
Official summary from Ping Identity
Summary: just on intercepting and going through the request i made from ort-admin.pingone.com . i found that the google map api key was leaking through get request . i was able to validate that the leaked key was a valid one Steps To Reproduce: 1.login to account goto setup tab > ping iD > device pairing goto add an ip and enter an ip click save and intercept the request have a look to the GET request and see the google map api key was leaked through request leaked key is █████ ███ i was able to validate thatt this key was a valid one by using an endpoint that validate the key https://maps.googleapis.com/maps/api/staticmap?center=40.714728,-73.998672&zoom=12&size=2500x2000&maptype=roadmap&key=XXXXX this shows that this is a valid key Impact any persons can use this api key for their own use
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$150.00
Submitted
Weakness
Information Exposure Through Sent Data