Loading HuntDB...

Access to microtransaction sales data for lots of apps from 2014 to present at /valvefinance/sanity/

Critical
V
Valve
Submitted None

Team Summary

Official summary from Valve

The Steamworks Product Data web site had an URL route with insufficient access controls, which would allow an authenticated partner to view data for games which they might not otherwise have permissions to view. After mitigation, an audit of accesses to this URL route showed no accesses by parties other than Valve or the reporter of this issue.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic