Issue 240: Spoutible API leakage, 15M Trello profiles scraped, API secret tokens leaked
Brief
This week, we have news of a record four API security related incidents. The first comes from Troy Hunt on a leakage on the new Spoutible social media site, with the second big ticket item being the leakage of 15 million profiles on Atlassian’s Trello. There’s also a report on the leakage of over 18,000 API tokens and the leakage of Office 365 accounts via a misconfigured server.
We also feature a guide on implementing basic authentication on Spring Boot.
Vulnerability: Vulnerabilities in Spoutible API
The first vulnerability this week comes to us from the founder of Have I Been Pwned , Troy Hunt, and features several significant vulnerabilities in the API of the new Spoutible social media platform. In Troy’s own words, “No way! No way!” — this is almost a case study on how not to implement an API. Let’s dig in — fasten your seatbelts.
