Sidekiq web UI (Ruby background processing) accessible unauthenticated via https://gift-test.starbucks.co.jp/sidekiq/busy

Disclosed: 2018-10-24 17:31:28 By jackds To starbucks
Medium
Vulnerability Details
**Summary:** I found the following URL, which appears to be running an Sidekiq web UI instance that is accessible unauthenticated: https://gift-test.starbucks.co.jp/sidekiq/busy **Description:** Sidekiq is used for Ruby background processing (as I've learned, I'm not really familiar with it). The web UI can be used to stop these processes, as can be seen here: {F359897} ## Steps To Reproduce: 1. Go to https://gift-test.starbucks.co.jp/sidekiq/busy ## Supporting Material/References: n.a. ## Impact Unclear. As the domain name suggests it might be a staging/test environment. I cannot determine clearly what these running processes are, but I am able to stop them which might be undesired.
Actions
View on HackerOne
Report Stats
  • Report ID: 423286
  • State: Closed
  • Substate: resolved
  • Upvotes: 16
Share this report