Publicly Accessible Datadog link

Disclosed: 2018-06-15 17:37:55 By rijalrojan To shopify
None
Vulnerability Details
During my daily scanning of shopify and shopify's internal domain (Shopify.io), I landed on a personal bookmark of an employee: █████████ who works at `Guru at Shopify`. The link for personal bookmark is here: ███ There is a personal bookmark called `██████████`. When going to the link: ████████ it loaded some stats about chat and talks: {F292195} ## Impact Leak of statistics regarding how many calls are waiting in support, how many are handled, average wait time etc.
Actions
View on HackerOne
Report Stats
  • Report ID: 345152
  • State: Closed
  • Substate: resolved
  • Upvotes: 18
Share this report