惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

I
InfoQ
C
CERT Recently Published Vulnerability Notes
The Last Watchdog
The Last Watchdog
P
Proofpoint News Feed
D
Darknet – Hacking Tools, Hacker News & Cyber Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
GbyAI
GbyAI
T
Tenable Blog
博客园 - 三生石上(FineUI控件)
P
Privacy & Cybersecurity Law Blog
Simon Willison's Weblog
Simon Willison's Weblog
Jina AI
Jina AI
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Tor Project blog
博客园_首页
F
Fortinet All Blogs
博客园 - Franky
Latest news
Latest news
Last Week in AI
Last Week in AI
T
Threat Research - Cisco Blogs
Scott Helme
Scott Helme
L
LINUX DO - 热门话题
U
Unit 42
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Hugging Face - Blog
Hugging Face - Blog
D
Docker
Project Zero
Project Zero
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
MongoDB | Blog
MongoDB | Blog
F
Full Disclosure
D
DataBreaches.Net
Google DeepMind News
Google DeepMind News
Cisco Talos Blog
Cisco Talos Blog
Y
Y Combinator Blog
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
H
Help Net Security
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
月光博客
月光博客
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Blog — PlanetScale
Blog — PlanetScale
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
S
Schneier on Security
C
Cybersecurity and Infrastructure Security Agency CISA
P
Proofpoint News Feed
PCI Perspectives
PCI Perspectives
Cloudbric
Cloudbric
V
Visual Studio Blog
Recorded Future
Recorded Future
人人都是产品经理
人人都是产品经理

Lobsters

CIFSwitch: a non-universal Linux local root vulnerability RIPE NCC session fixation: poaching logins with an Atlas probe GNOME 2.20 but its Web Components Agentic Search for Context Engineering – Leonie Monigatti Garnix is shutting down [not OC] akashina.tngl.sh/jjc Concerning Emacs (and Jazz) Nitpicking the shell history scene in ‘Tron: Legacy’ What's cooking on SourceHut? Q2 2026 The tenth OpenPGP email summit Package managers that package package managers Clojure on Fennel part three: parsing WordPress at 23 Finding Miscompiles for Fun, Not Profit GitHub - creusot-rs/creusot: Creusot helps you prove your Rust code is correct. Announcing Rust 1.96.0 | Rust Blog A Love Letter to Neovim sqlite AGENTS.md Am I a Bad Friend? CSS vs. JavaScript • Josh W. Comeau Erlang Ecosystem Foundation - Supporting the BEAM community A brief note about slot access cost in Common Lisp Keyboard latency probe Rethinking the GNOME clipboard issues Back to the Building Blocks’ Building Blocks Tech Notes: Theseus: translating win32 to wasm Fast is better than slow Content-addressed Rust builds (or, what kache actually caches) Intent to Prototype: Embedding API Canada’s Bill C-22 and the security cost of collecting more data 5 PostgreSQL locking behaviors that trip people up okmij.org Stop advertising in your commits! | AksDev GitHub - mplsllc/macsurf: A modern web browser for Classic Mac OS 9 PowerPC. Real CSS3, ES5 JavaScript, native HTTPS — built with CodeWarrior on the Carbon API. Introducing DoomBench - Can Your Data Stack Run DOOM? What are some of your favourite developer tools? Building a Scalable Ingestion Pipeline with Temporal (Part 1) Converting shallow Git bundles into normal repositories Are you a member of any professional associations? What is a harmonic? An interactive comic about additive synthesis How Virtual Tables Work in the Itanium C++ ABI Using SwiftUI to Build a Mac-assed App in 2026 Rust (and Slint) on a jailbroken Kindle. ~jack/lambda-on-lambda - Serverless Haskell on AWS - sourcehut git Human proof for FOSS contributions Extremely simple internet radio controlled via IRC Announcing BABLR Splitting Konsole views from Helix to run tools | AksDev GitHub - yugr/rust-slides Serving files over HTTP three ways: synchronous, epoll, and io_uring update docs with information about building with build.py (#979) · astral-sh/python-build-standalone@c9c40c5 A Simple Makefile Tutorial On C extensions, portability, and alternative compilers Switching to Colemak | Pedro Alves Just How Bad Was The Intel IAPX432? Nix's Substituter List Is Not a Routing Table Accelerating copy_if using SIMD Lambda on Lambda: Serverless Haskell on AWS | Blog Announcing feed-repeat v1.0 Scaling Akvorado BMP RIB with sharding EYG news: A host of CLI improvements, new guides and new effects The social contract of writing JS Crossword C array types are weird; and related topics Flatpak will depend on systemd – OSnews Migrating from Go to Rust | corrode Rust Consulting A portentous reunion Vivado Licensing Options How my minimal, memory-safe Go rsync steers clear of vulnerabilities the entropy layer of a wavelet codec, on its own GitHub - nferhat/fht-compositor: A dynamic tiling Wayland compositor. Debian SE Linux and PinTheft Does bulk memmove speed up std::remove_if? (No.) 声明式部分更新 | Blog | Chrome for Developers Fully in-browser container builds Dianne Skoll's Web Site - Remind The Architecture of Open Source Applications (Volume 1)Berkeley DB Pardon MIE? - ironPeak Blog “Long-Term Support” doesn’t mean what you think Jira IS Turing-Complete May I recommend thinking of Emacs as your Fortress of Solitude hershey Floodgap Gopher-HTTP gateway gopher://thelambdalab.xyz/1cuneiforth/ HP QuickWeb, Singular And Pointless That one time I used Go panics for flow control A new suite of modern tools coming for editing and publishing RFCs From the Tabletop… The Digital Antiquarian Building a Host-Tuned GCC to Make GCC Compile Faster Are we self-sovereign PKI yet? Claw Patrol: an open-source security firewall for agents | Deno Revised^7 Report on Scheme, Large: Procedural Fascicle Draft is now public A Network Allow-List Won't Stop Exfiltration — André Graf From AFSK to Goertzel – µArt.cz Software For My New Home Server Introducing Neptune: Direct3D virtualization for QEMU AI Agent Bankrupted Their Operator While Trying to Scan DN42 - Lan Tian @ Blog mimalloc: A new, high-performance, scalable memory allocator for the modern era Making wl_shm fast The Soul of Maintaining a New Machine - Third Draft | Books in Progress What is Git made of?
Exploiting vulnerabilities in Johnson & Johnson web apps
Eaton · 2026-06-25 · via Lobsters

Eaton

Today I am revealing vulnerabilities I found in 2 very different Johnson & Johnson web apps. One is a vulnerability in a college campus recruiting system that exposed details of nearly 1,000 students, and the other is an admin takeover of an internal audit system used by 20 companies. Let’s dive in!

#1: Campus Recruiting

You know those career fairs and recruiting events on college campuses? JnJ likes to go to these to scout new talent. They built a “Campus Recruiting” website to manage these events:

Students are given an event key and they use it to submit their information:

Nothing particularly exciting… until you look at the underlying code of the website, where you can find some interesting private recruiter routes!

When you go to “/recruiter”, you are sent to the Microsoft SSO login page, confirming this part of the site is restricted to JnJ employees:

The authentication setup is really simple. The Microsoft Authentication Library (MSAL) is integrated into the frontend and it is in charge of making sure an employee is logged in:

One client-side trick that often helps me expose insecure web apps is to hack MSAL into always thinking someone is logged in. If there are underlying APIs that do not use the token correctly, this helps discover such issues quickly. In this case, all I had to do was modify the MSAL code to always return details of 1 account that is “logged in”:

Once done, the private recruiter routes were accessible. You could manage the events, create new ones, and view all the students’ information. The recruiter dashboard also lets you see the ratings and notes they give to specific students they interview:

What went wrong: the MSAL token was not actually used anywhere. Instead, a hardcoded API key was used to authenticate to their AWS APIs:

There were nearly 1,000 students impacted.

The Campus Recruiting site has since been updated to replace API key authentication with Bearer token (MSAL) authentication.

#2 Audit Tracking Management System

The Audit Tracking Management System (ATMS) is an internal web app to aid in managing audits across all of JnJ and their associated companies:

  1. LifeScan
  2. Ethicon, Inc
  3. Biosense Webster
  4. ITS
  5. Depuy
  6. Ethicon-Endo
  7. Janssen
  8. Vistakon
  9. Acclarent
  10. JDx
  11. Sterilmed
  12. CLS
  13. JJSV
  14. Cerenovus
  15. EQ
  16. Janssen UK & Ireland
  17. RAD
  18. Abiomed Inc.
  19. CQ MedTech
  20. V-Wave

This one required a bit more work to get into compared to Campus Recruiting. Immediately when visiting the site, you are redirected to the Microsoft SSO login page. Before this happens, the ReactJS app is downloaded and many interesting APIs could be found:

I decided to visit the “getAllUsers” API to see what would happen. It returned a list of 13.6k JnJ employees:

That was huge because it indicated all the APIs were unauthenticated, and it was just a matter of hacking up the client-side code to get full access to everything.

This is what the authentication code looked like. Like Campus Recruiting, it uses MSAL to authenticate the user using Microsoft SSO, and then it sets some values to local storage. There is no sign of it using the Bearer token, which is good for us!

For a user spoof to work correctly, I needed to find a username and WWID of a valid JnJ employee that uses this system. Preferably one with a lot of permissions. I came across the help page that gave me the details of the system administrator:

Searching that name against users in the getAllUsers API revealed the information I needed, and a patch was devised:

This stops the login redirect and sets hardcoded values into local storage as if a valid login had just taken place. This resulted in something new showing up:

Clicking OK was not the solution. Back into the code we go…

That is the code that creates a session. It is just a GET request to an API that returns a session GUID, and sets a timestamp for the purpose of calculating its expiry. Visiting that API, it returned a valid session ID:

I then plugged that in manually with a valid timestamp…

Refreshed, and I was in!

You can use the drop-down to switch between companies:

As admin, I had access to a special menu:

And that is about the extent of what I explored. The system is packed full of presumably confidential information and transcripts. Even from all the way over in Russia. Due to various confidentiality warnings, I have opted to not show any internal meeting minutes or transcripts here.

Bonus: they used a rather dumb client-side encryption scheme to try and obscure some secret values. Ironically, it seems this auditing system never received an audit itself if code like this ends up being published:

Timeline

The last time I reported a security vulnerability to JnJ was back in 2024. The experience I had back then was stellar – they took immediate action and were a true pleasure to work with. Fast forward to reporting these 2 vulnerabilities, the experience was less positive.

Both vulnerabilities were reported to them in October 2025. By the end of the month, they had resolved the Campus Recruiting vulnerability. However, the ATMS vulnerability was never acted upon. I followed up for months until April 2026, which is when I asked a journalist friend if they could help move things along. As predicted, their email to JnJ’s media relations finally got them to fix it. It was a bit perplexing that it took press involvement to address what I believed was a serious internal data breach waiting to happen.

Full timeline:

  • October 6, 2025: Reported to JnJ’s Vulnerability Reporting Program.
  • October 16, 2025: Followed up after no response and no action.
  • October 17, 2025: First response from JnJ received confirming they will look into the findings.
  • October 31, 2025: Campus Recruiting vulnerability fixed; I ask about ATMS.
  • November 17, 2025: Followed up after no response and no action on ATMS.
  • December 22, 2025: Followed up after no response and no action on ATMS.
  • January 22, 2026: Followed up after no response and no action on ATMS.
  • April 8, 2026: Journalist contacted.
  • April 21, 2026: ATMS vulnerability finally fixed.
  • June 24, 2026: Published

Not the best showing for JnJ here. It seemed they were a lot more effective at handling vulnerabilities back in 2024 compared to 2025. I hope they correct whatever broke down in this process so they can return to the amazing reporting experience I had with them back in 2024.

Subscribe to new posts

Get an email notification every time something new is published.