Shopify's SF and LA offices Dashboard Information disclosed via Public Gist

Disclosed: 2019-11-06 13:12:10 By ehsahil To shopify
Unknown
Vulnerability Details
Hi Team, During my recon process, I found a public gist containing the Internal Information of the Shopify offices of LA and SF. The gist belongs to the Shopify employee - https://gist.github.com/runmad (He is currently - Engineering Manager at Shopify) LA Office Dashboard - https://gist.github.com/runmad/333bc33095f6f40ee8fb606fff94fbdb/revisions SF Office Dashboard - https://gist.github.com/runmad/1e820c6b02d6279914d9bcb8a2a3b9cc/revisions The disclosed information contains the Shopify employee email addresses and calendar details. █████████ There are more than 300 revisions on both the gists. ## Impact The gist disclosing the Internal information regarding the Shopify employees. Please let me know if you need more information from my side. Thanks @ehsahill
Actions
View on HackerOne
Report Stats
  • Report ID: 729040
  • State: Closed
  • Substate: resolved
  • Upvotes: 12
Share this report