[Information Disclosure] Amazon S3 Bucket of Shopify Ping (iOS) have public access of other users image

Program: shopify Bug Type: Information Disclosure Bounty: 2900 Date: 2020-10-29
sensitive-data-exposure cryptographic-failure misconfiguration

Summary

Shopify ping is a shopify mobile application that enables integration with an already used chat platform, allowing centralization. The researcher found an exposed amazon s3 bucket with directory listing enabled exposing shared user images from private chats, This endpoint was discovered when testing the chat app, and the researcher noticed that the send images where stored in an s3 bucket owned by shopify.

References