
Summary: Stripo uses Spring boot for the backend API development , and misconfigured the application to open actuator APIs to the public. This issue is found in 3 domains , don't know if I need to publish 3 reports for that, or just one report , but the domains are : https://my.stripo.email/cabinet/stripeapi/actuator https://plugins.stripo.email/actuator https://plugin.stripo.email/actuator it might be available in other micro services as well Steps To Reproduce: Go to the following URL : https://my.stripo.email/cabinet/stripeapi/actuator/heapdump This url will download the heap dump of the server using a memory analyzer such as Eclipse memory analyzer or VisualVM open the downloaded file By searching inside the file you can find all the secrets , credentials , urls , JWT tokens & JWT secret keys, which can be used and generate any JWT token and takeover any account on the system. Attached some examples of what can be found and used by this vulnerability, and you can imagine any bad scenario, and this issue can be used to take over/down Stripo Supporting Material/References: Please find more information about actuator on the following URL: https://docs.spring.io/spring-boot/docs/current-SNAPSHOT/actuator-api/html/#heapdump Example of open functionalities: {F696196} Admin Credentials: {F696186} Other User's information: {F696189} Billing Service Credentials: {F696190} Config Server Credentials: {F696191} Impact This vulnerability allows any attacker to perform many severe...
SOCIAL SHARE CARD GENERATOR