Messages disclosure via search feature of other users group(Cross-Tenant).
Medium
L
Lark Technologies
Submitted None
Team Summary
Official summary from Lark Technologies
Due to a Insecure Direct Object Reference (IDOR) vulnerability identified within the message search function of Lark, an attacker could have potentially viewed messages, docs, and attachments shared in other users groups. We thank @base_64 for reporting this to our team and verifying the resolution.
Actions:
Reported by
base_64
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Direct Object Reference (IDOR)