Disable caching for account pages with sensitive information

A vulnerability test revealed that account pages with sensitive information are cached. It was considered a low severity vulnerability but should be addressed as soon as possible. Can a Shopify dev please look into this?

Severity: Low

Steps to reproduce:

  1. Go to any Shopify store website.
  2. Log in to your account.
  3. View any /account page that contains sensitive information.
  4. Log out of the account.
  5. Press back on the browser.
  6. Sensitive information can still be viewed because it was cached.

Possible solution:

Add the Cache-Control HTTP response header such as Cache-Control: no-store. It will help ensure that the browser does not cache sensitive pages.

Please advise.

Thanks!

Hi @Winbox

Thank you so much for reaching out and sharing this find. I will ensure it is reported to our security teams for a review, but I would also encourage you to submit this through our Bug Bounty program on HackerOne.

Our security team who handles site vulnerabilities receive all reports in there directly and could also make you eligible for a bounty reward as well.

Hi Shay,

Thank you for the speedy response. I hope this gets recognized and resolved soon. Any way I can be notified of new updates? I signed up for HackerOne but it’s a bit too much for me to grasp. I’ll just wait for you all to do your thing.

Thanks!

Hi @Winbox

No worries, I took a look at the HackerOne reporting and it is pretty intense! I’ve made our team aware and they will assess if this is a security concern and address that if needed. Updates on those kind of changes can usually be found in our Developer Changelog.