Huge OneFly data breach sees traveler IDs and payment details leaked



  • OneFly leaked thousands of sensitive customer records via unsecured Elasticsearch instance
  • Data included names, IDs, flight details, full credit card info, and JWT tokens
  • Cybernews urges access controls, refined logging, and IP whitelisting to mitigate risks

Travel technology and flight content company OneFly has apparently leaked thousands of sensitive customer records, including unedited payment information, online.

Security researchers from Cybernews said they recently discovered “thousands of records” leaking from nine internal Java Spring Applications in real-time, through an Elasticsearch instance.


https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img