Skip to main content
Participant
January 17, 2022
Question

PDF Redaction Vulnerability

  • January 17, 2022
  • 4 replies
  • 574 views

I have found a vulnerability that enabled an individual's redacted name and email address to be found from a publicly posted PDF. This is a serious security vulnerability for those using Acrobat's Redaction feature. Where may I contact the dev or bug bounty team?

 

Aidan

This topic has been closed for replies.

4 replies

try67
Community Expert
Community Expert
January 17, 2022

Can you post an example file that demonstrates this bug? Also include the original file and the exact steps you took, please.

Dave Creamer of IDEAS
Community Expert
Community Expert
January 17, 2022

When you redact, one of the options is to "sanitize" the document. If you skipped this step, information could be left in the document. 

David Creamer: Community Expert (ACI and ACE 1995-2023)
Bevi Chagnon - PubCom.com
Legend
January 17, 2022

Although the visible text might have been redacted, was that information still left in the PDF's metadata?

File / Properties and choose the 1st thumbtab Description.

 

|    Bevi Chagnon   |  Designer, Trainer, & Technologist for Accessible Documents ||    PubCom |    Classes & Books for Accessible InDesign, PDFs & MS Office |
Bernd Alheit
Community Expert
Community Expert
January 17, 2022

Where have you found the name and address?