Firebase Collection Disclosure

medium Web App Scanning Plugin ID 115471

Synopsis

Firebase Collection Disclosure

Description

The Firebase Realtime Database on the remote host allows unauthenticated read access to its collection data. Appending '.json' to a node path returns its content, which may include user records or other private information.

Solution

Restrict read access in the Firebase Realtime Database security rules to authenticated principals.

Plugin Details

Severity: Medium

ID: 115471

Type: Check Based

Published: 9/14/2026

Updated: 9/14/2026

Scan Template: api, basic, full, pci, scan

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS Score Source: Tenable

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Reference Information