Researchers Claim Fiverr User Data Is Exposed in Google Search Results
ID: a88d9d4a-97d4-5a5a-a70f-df379f0c2c05
STIX ID: report--a88d9d4a-97d4-5a5a-a70f-df379f0c2c05
Feed Name: Cyber Press
A security researcher disclosed that Fiverr improperly configured Cloudinary to serve private client–freelancer attachments via public, non-expiring URLs, causing sensitive documents (including IRS Form 1040s and other PII) to be discoverable and indexed by Google. The exposure stems from lack of access controls and public HTML pages linking to the assets; the researcher reported the issue to Fiverr 40 days earlier with no acknowledgment. Remediation advised includes switching to signed/expiring URLs, revoking public access to the Cloudinary storage, and requesting removal from search caches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
