BIM360 security hole

So it turns out that if you download a file from BIM360 (any file, PDFs, IFCs, Revit files) the download link it generates is publicly accessible and doesn't require any authentication. Here's an example:

https://developer.api.autodesk.com/oss/v2/signedresources/5707f4f9-8050-406a-9b8b-c14a9940b8fa?region=US&response-content-type=application/octet-stream

UUID collision is obviously very low, but just a heads up don't share these links since the public can access them. It's pretty unlikely but probably worth mentioning. I don't know if these links expire either, so we'll find out.

paulleehtlcnnJanFMeetlatinfeeeeejchkoch

Comments

Sign In or Register to comment.