Unauthenticated Create, Read, and Delete of Any User's Data + Email Relay on JPL Hurricane Watch

Disclosed by
Aman12321
Summary by Aman12321

Identified a broken access control vulnerability (P1/Critical) on a NASA/JPL production web application. The application's API allowed unauthenticated users to create, read, and delete any user's saved data using only a name as the identifier - with no session, cookie, or token required. Additionally, an unauthenticated email relay endpoint was discovered. The issue was triaged, confirmed, and resolved by NASA's security team.

Activity