Loading HuntDB...

GCM sender key leak

Low
H
hostinger
Submitted None

Team Summary

Official summary from hostinger

Summary: During the recon phase, I have observed that GCM sender key is stored in clear text can be viewed in browser. The key is required so that Chrome, Opera for Android and the Samsung Browser can use the Firebase Cloud Messaging (FCM) API. The goal is to use the Web Push Protocol when the standard is finalized and FCM can support it. The key is unique and should not be disclosed. There should be proper authorization to it. Closure conclusion: Manifest and the key are no longer used and serve no purpose, so they were deleted.

Reported by cracko

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Cleartext Storage of Sensitive Information