GCM sender key leak
Low
H
hostinger
Submitted None
Team Summary
Official summary from hostinger
Summary: During the recon phase, I have observed that GCM sender key is stored in clear text can be viewed in browser. The key is required so that Chrome, Opera for Android and the Samsung Browser can use the Firebase Cloud Messaging (FCM) API. The goal is to use the Web Push Protocol when the standard is finalized and FCM can support it. The key is unique and should not be disclosed. There should be proper authorization to it. Closure conclusion: Manifest and the key are no longer used and serve no purpose, so they were deleted.
Actions:
Reported by
cracko
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Cleartext Storage of Sensitive Information