Skip to main content

Firebase Data Exposure Vulnerability

A significant data exposure vulnerability has been discovered in Google Firebase development platform for web and mobile applications which can leak sensitive data from backend servers. The exposed data includes Personally Identifiable Data (PID), Special Personally Identifiable Data (SPID) and plain text passwords.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A significant data exposure vulnerability has been discovered in Google Firebase development platform for web and mobile applications which can leak sensitive data from backend servers. The exposed data includes Personally Identifiable Data (PID), Special Personally Identifiable Data (SPID) and plain text passwords.

Threat details

The data is exposed by mobile app developers failing to require authentication to the Firebase cloud database. Attackers can gain access to unprotected data by just adding "/.json " with a blank database name at the end of the hostname for example;

  • Sample API URL: https://<Firebase project name>.firebaseio.com/<database.json>
  • Payload to access data: https://<Firebase project name>.firebaseio.com/.json

The Google Firebase service does not secure user data by default unless the developer configures them. An attacker could exploit the data records from the open mobile application databases.


Remediation steps

Type Step
Organisations using or developing applications using Firebase should contact their relevant suppliers to ensure these applications are secure.

Last edited: 17 February 2020 12:43 pm