HackerOne Staging uses Production data for testing

Disclosed: 2021-11-05 20:52:15 By tk0 To security
Low
Vulnerability Details
**Summary:** Today I received an email related to smart rewards from HackerOne. This included staging environment details, such as: ``` sender: [email protected] Privacy / Terms links pointing to domain: https://www.enorekcah.com/... ``` This basically tells us that HackerOne is using hacker data (real users) in their lower environment (STAGING). Usually this should be avoided and production data should not be copied into lower environments -> using live data for testing. See attachment which holds a copy of received email: ████ ## Impact Privacy issues related to customer/hacker data in HackerOne. Cheers! @tk0
Actions
View on HackerOne
Report Stats
  • Report ID: 1392511
  • State: Closed
  • Substate: resolved
  • Upvotes: 58
Share this report