[Information Disclosure] Amazon S3 Bucket of Shopify Ping (iOS) have public access of other users image
Program: shopify
Bug Type: Information Disclosure
Bounty: 2900
Date: 2020-10-29
sensitive-data-exposure
cryptographic-failure
misconfiguration
Summary
Shopify ping is a shopify mobile application that enables integration with an already used chat platform, allowing centralization. The researcher found an exposed amazon s3 bucket with directory listing enabled exposing shared user images from private chats, This endpoint was discovered when testing the chat app, and the researcher noticed that the send images where stored in an s3 bucket owned by shopify.