Loading HuntDB...

Google Maps API key leaked during device pairing

Medium
P
Ping Identity
Submitted None

Team Summary

Official summary from Ping Identity

Summary: just on intercepting and going through the request i made from ort-admin.pingone.com . i found that the google map api key was leaking through get request . i was able to validate that the leaked key was a valid one Steps To Reproduce: 1.login to account goto setup tab > ping iD > device pairing goto add an ip and enter an ip click save and intercept the request have a look to the GET request and see the google map api key was leaked through request leaked key is █████ ███ i was able to validate thatt this key was a valid one by using an endpoint that validate the key https://maps.googleapis.com/maps/api/staticmap?center=40.714728,-73.998672&zoom=12&size=2500x2000&maptype=roadmap&key=XXXXX this shows that this is a valid key Impact any persons can use this api key for their own use

Reported by bug_digger21

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$150.00

Submitted

Weakness

Information Exposure Through Sent Data