Security researcher claims airport group exposed API keys for four years
UKPulse Health Desk
A security researcher reportedly believes an airport group left API keys in client-side JavaScript for four years, potentially exposing 8.8 million customer records.
- A security researcher claims an airport group exposed API keys in client-side JavaScript.
- The exposure reportedly lasted for four years.
- The researcher believes this could have exposed 8.8 million customer records and enabled mass deletion.
A security researcher has claimed that an airport group reportedly left API keys in client-side JavaScript for a period of four years. This alleged exposure is believed to have potentially compromised 8.8 million customer records.
The researcher also suggests that these overprivileged Iterable credentials could have allowed for the mass deletion of data.