logo

228 Business information leak - Analytics


Description

Business insights from mobile app usage analytics are obtained via a Swagger URL exposed along with the APIKey.


Impact

Obtain business information about the analytics of the mobile application.


Recommendation

According to the classification of the found information, establish the necessary controls so that the information is accessible only to the indicated persons.


Threat

Unauthenticated external attacker in the application.


Expected Remediation Time

30 minutes.


Score 4.0

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

  • Attack vector: N
  • Attack complexity: L
  • Attack Requirements: N
  • Privileges required: N
  • User interaction: N
  • Confidentiality (VC): L
  • Integrity (VI): N
  • Availability (VA): N
  • Confidentiality (SC): N
  • Integrity (SI): N
  • Availability (SA): N

Threat 4.0

  • Exploit maturity: X

Requirements


Fixes


Last updated

2024/02/16