HackerOne Staging uses Production data for testing
Low
Vulnerability Details
**Summary:**
Today I received an email related to smart rewards from HackerOne. This included staging environment details, such as:
```
sender: [email protected]
Privacy / Terms links pointing to domain: https://www.enorekcah.com/...
```
This basically tells us that HackerOne is using hacker data (real users) in their lower environment (STAGING). Usually this should be avoided and production data should not be copied into lower environments -> using live data for testing.
See attachment which holds a copy of received email: ████
## Impact
Privacy issues related to customer/hacker data in HackerOne.
Cheers!
@tk0
Actions
View on HackerOneReport Stats
- Report ID: 1392511
- State: Closed
- Substate: resolved
- Upvotes: 58