Apple kafka server Sensitive info disclosure including secret keys and api keys on https://gsp9-ssl.ls.apple.com

Company Information : 

Apple Inc. is an American multinational technology company headquartered in Cupertino, California. As of March 2023, Apple is the world's biggest company by market capitalization, and with US$394.3 billion the largest technology company by 2022 revenue.


Bug Category : 

Netowork Recon 

Parameter Brute force 

Information disclosure 



#Effected Service :

https://gsp9-ssl.ls.apple.com



##Vulnerable URL:

https://gsp9-ssl.ls.apple.com/check?config=



#Description of the issue :

The above mentioned Vulnerable URL discloses very sensitive information regarding Kafka configuration and it also includes 

Secret keys and api keys. 

I haven't tested and used these keys anywhere. I am mentioning below some data I found.

Ex :

massilia-config.secret-key":"\"\"

fare_api_key":"\"





##Steps to reproduce :

Run the below mentioned URL in Browser.

https://gsp9-ssl.ls.apple.com/check?config=

It will show you all configuration details of Kafka server.



#POC :

I am attaching a screenshot of the page.

Screenshot 2021-05-10 at 2.38.30 PM.png




#Impact :

Apple kafka server Sensitive info disclosure including secret keys and api keys on https://gsp9-ssl.ls.apple.com


Timeline : 








May 10th 2021: Report send to Apple product Security Team through Email.

May 11th 2021 : Report Accepted and Triaged.

June 22th 2021 : Complete issue was resolved and confirmed.

June 08th 2021 : 2500$ Bounty Rewarded


Comments

Popular posts from this blog

Account Takeover Apple App Store Connect Account of Any user and Steal Developer API/Subscription Keys of any user(CORS+XSS) worth 8500$

Amazon Web Services : Takeover Workbook and delete the Owner on https://builder.honeycode.aws by collaborator user (IDOR) worth 7200$

UnAuth Access to Twitter Private Tweets and messages Media Content Access(IDOR)