← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 11, 2021 · 22:00via API Security News

Issue 146: Facebook API leaking private group membership, JWT Attacker plugin for Burp

Brief

This week, we have the recent API fix involving group membership at Facebook, a case study of a BOLA vulnerability leaking users’ credit coupons, a handy add-on for Burp Suite, plus an interview with a security expert on API security.

Vulnerability: Facebook

Facebook API was leaking information on users’ memberships in private groups. Muhammad Sholikhin found that he could verify if someone was a member of a private Facebook group , as long as the attacker and the victim were connected (friends) in Facebook. Membership information on private Facebook groups is not supposed to be visible to anyone outside the group.

Read more on API Security News