← Back to feed
Vulnerabilities & PatchesEmerging1 sourceJan 13, 2022 · 07:22via API Security News

Issue 167: Uber bug allows spoof emails, partner-facing APIs on the rise, omnichannel APIs increase risk

Brief

This week, we have a long-standing vulnerability on a public-facing internal API on Uber, which allowed attackers to spoof emails. In addition, there’s an article by NordicAPIs on the RapidAPI report into the rise on partner-facing APIs, IBM’s views on the API security risk posed by the growth in omnichannel APIs, and finally (another) awesome API security mega guide.

Vulnerability: Uber bug allows attackers to spoof emails

This week, ThreatPost featured details of a vulnerability on a public-facing internal API on Uber allowing attackers to spoof emails so that they would appear to be from Uber.

Details of the vulnerability were disclosed by a Seekurity security researcher and bug-hunter Seif Elsallamy, who made efforts to disclose details to Uber both directly and by submitting it to HackerOne.

Read more on API Security News