SpaceX debug page accessible when using Starlink

Disclosed by
JP_Bennett's avatar
JP_Bennett
  • Engagement SpaceX/Starlink
  • Disclosed date about 3 years ago
  • Reward $4,800
  • Priority P2 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by SpaceX/Starlink

While standing up new ground infrastructure, we exposed unauthenticated services externally. We appreciate this report that helped us quickly identify and remediate this in a responsible way.

Summary by JP_Bennett

Internal IPs discovered via a simple Traceroute had exposed ports when visiting from a Starlink ISP connection. What looked like an information disclosure only, was soon confirmed to be more serious due to an exposed GRPC endpoint that was unauthenticated.

Activity
  1. tim’s avatar
    tim Customer sent a message

    ()

  2. JP_Bennett’s avatar
    JP_Bennett sent a message

    ()

  3. tim’s avatar
    tim Customer sent a message

    ()

  4. tim’s avatar
    tim Customer published the disclosure report

    ()

  5. JP_Bennett’s avatar
    JP_Bennett sent a message

    ()

  6. tim’s avatar
    tim Customer sent a message

    ()

  7. JP_Bennett’s avatar
    JP_Bennett sent a message

    ()

  8. JP_Bennett’s avatar
    JP_Bennett requested disclosure

    ()

  9. tim’s avatar
    tim Customer changed the state to Resolved

    ()

  10. tim’s avatar
    tim Customer rewarded JP_Bennett 20 points

    ()

  11. tim’s avatar
    tim Customer rewarded JP_Bennett $4,800

    ()

  12. tim’s avatar
    tim Customer sent a message

    ()

  13. tim’s avatar
    tim Customer changed the severity to P2

    ()

  14. viper-bugcrowd’s avatarbugcrowd logo
    viper-bugcrowd changed the state to Triaged

    ()

  15. viper-bugcrowd’s avatarbugcrowd logo
    viper-bugcrowd changed the severity to P4

    ()

  16. JP_Bennett’s avatar
    JP_Bennett sent a message

    ()

  17. jbaizer’s avatar
    jbaizer Customer sent a message

    ()

  18. JP_Bennett’s avatar
    JP_Bennett created the submission

    ()