Firebase Data Exposure Vulnerability
A significant data exposure vulnerability has been discovered in Google Firebase development platform for web and mobile applications which can leak sensitive data from backend servers. The exposed data includes Personally Identifiable Data (PID), Special Personally Identifiable Data (SPID) and plain text passwords.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
A significant data exposure vulnerability has been discovered in Google Firebase development platform for web and mobile applications which can leak sensitive data from backend servers. The exposed data includes Personally Identifiable Data (PID), Special Personally Identifiable Data (SPID) and plain text passwords.
Threat details
The data is exposed by mobile app developers failing to require authentication to the Firebase cloud database. Attackers can gain access to unprotected data by just adding "/.json " with a blank database name at the end of the hostname for example;
- Sample API URL: https://<Firebase project name>.firebaseio.com/<database.json>
- Payload to access data: https://<Firebase project name>.firebaseio.com/.json
The Google Firebase service does not secure user data by default unless the developer configures them. An attacker could exploit the data records from the open mobile application databases.
Remediation steps
Last edited: 17 February 2020 12:43 pm