Flair Airlines left database and email credentials exposed on its website
- Organization
- Flair Airlines
- Exploit
- Misconfiguration
- Industry
- Airline
Flair Airlines, a Canadian ultra low cost carrier, left environment configuration files publicly readable on its flyflair.com website, according to research published by Cybernews in September 2023. Environment files hold application secrets such as API keys and database credentials and are not meant to be reachable from the public internet.
The exposed files contained MySQL credentials and host details for a local database and for a second database that was reachable over the internet, SMTP configuration and credentials for two Flair sending addresses, and a Laravel application key. Researchers said anyone who found the files could have connected directly to the internet-facing database and read, copied or, depending on privileges, altered its contents. They also warned that the mail credentials would have allowed messages to be sent from official Flair addresses.
At least one Flair subdomain used for group travel bookings collected passenger names, email addresses, phone numbers and flight details including destinations, dates and flight numbers. Flair's privacy policy also lists gender, address and date of birth among the data it collects, so those fields were potentially at risk.
Cybernews said the files were first indexed in August 2022 and were found on February 27, 2023, leaving them accessible for around seven months. Disclosure began in March 2023 and required repeated follow ups, including a report to Canada's national computer emergency response team, before the exposure was closed. Flair did not respond to requests for comment, and no public evidence emerged that the credentials were abused.