THREAT OPS › Threat News › [GHSA] GHSA-q9c5-pp7m-fm2g (medium) — Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
[GHSA] GHSA-q9c5-pp7m-fm2g (medium) — Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
GHSA-q9c5-pp7m-fm2g Severity: medium CVE: None
Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
### Summary
Two endpoints serving in-house iOS application packages and manifests in Fleet's enterprise tier are reachable without a hard-to-guess token in the URL, allowing an unauthenticated attacker who can reach the Fleet server to download an in-house IPA by gues
Indicators of compromise
- https://join.slack.com/t/osquery/shared_invite/zt-h29zm0gk-s2DBtGUTW4CFel0f0IjTEwurl
- security@fleetdm.comemail
Original source: https://github.com/advisories/GHSA-q9c5-pp7m-fm2g