tl;dv 회의 기록 플랫폼에서 사용자 데이터가 무방비로 노출됐다.
AI 회의 기록 플랫폼 tl;dv의 Firestore에서 테넌트 격리가 부적절하게 이루어져, 무료 계정으로 다른 사용자의 회의 메타데이터에 접근할 수 있는 문제가 발생했다. 노출된 정보에는 생성자 이메일, Google Meet 및 Teams 회의 ID 등이 포함되어 있으며, 이는 보안 문제를 일으킬 수 있다. 사용자는 이러한 위험을 인지해야 하며, 플랫폼의 보안 강화를 요구해야 한다.
User data exposed in tl;dv meeting records platform due to lack of tenant isolation.
The AI meeting recording platform tl;dv has faced a serious security issue as tenant isolation was improperly implemented in its Firestore. Free account users could access metadata from other users' meetings, including creator emails and Google Meet and Teams meeting IDs. This raised significant concerns over user privacy and security. Users should be aware of these risks and demand stronger security measures from the platform.