Collected research
Authorization bypass due to cache misconfiguration
A short-lived server-side cache on an e-commerce admin GraphQL endpoint stored the order-listing response without including the caller's authorisation in the cache key. This bug bounty write-up shows that a low-privilege user replaying the same operation with a publicly known shop identifier inside the three-to-four second window received the cached administrator response, exposing order and customer data even though the endpoint otherwise returned 403 to that user.
Record
- Researcher
- Rikesh Baniya
- Published by
- Medium
- Date
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Rikesh Baniya, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .