More

    Huge OneFly data breach sees traveler IDs and payment details leaked



    • OneFly leaked thousands of sensitive customer records via unsecured Elasticsearch instance
    • Data included names, IDs, flight details, full credit card info, and JWT tokens
    • Cybernews urges access controls, refined logging, and IP whitelisting to mitigate risks

    Travel technology and flight content company OneFly has apparently leaked thousands of sensitive customer records, including unedited payment information, online.

    Security researchers from Cybernews said they recently discovered “thousands of records” leaking from nine internal Java Spring Applications in real-time, through an Elasticsearch instance.


    https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-2560-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img