Skip to main content

Emails of ALL Gainsight end-users are exposed in an Externally Shared C360 layout

  • March 7, 2024
  • 7 replies
  • 483 views

Tomas Trijonis

While fiddling around within the Gainsight Weekly Usage Highlights I’ve discovered that it’s quite easy to manipulate the filters to see emails of what only can be explained as all users of Gainsight from all customers. Not contacts and not just our end-users. Literally anyone who has ever touched Gainsight...
 

 

March 7, 2024

Thank you again for flagging this @Tomas Trijonis.  We have investigated and can acknowledge that there was an issue. To clarify, the contacts from Gainsight customer instances were not exposed - rather, it was some contacts from Gainsight’s own instance of CS that were visible through the email filter. We have now implemented a fix. We’re evaluating the impact and will share more details as needed.

7 replies

alizee
Forum|alt.badge.img+13
  • VIP ⭐️⭐️⭐️⭐️⭐️
  • March 7, 2024

While fiddling around within the Gainsight Weekly Usage Highlights I’ve discovered that it’s quite easy to manipulate the filters to see emails of what only can be explained as all users of Gainsight from all customers. Not contacts and not just our end-users. Literally anyone who has ever touched Gainsight...
 

 

Needs fixing ASAP. 


Kenneth R
Forum|alt.badge.img+5
  • Expert ⭐️⭐️
  • March 7, 2024

Hi, thank you for flagging!  We’re looking into it and will follow-up asap.


romihache
Forum|alt.badge.img+9
  • VIP ⭐️⭐️⭐️⭐️⭐️
  • March 7, 2024

Oh my… I liked but you know, I don’t actually like this 😱


Kenneth R
Forum|alt.badge.img+5
  • Expert ⭐️⭐️
  • March 7, 2024

Thank you again for flagging this @Tomas Trijonis.  We have investigated and can acknowledge that there was an issue. To clarify, the contacts from Gainsight customer instances were not exposed - rather, it was some contacts from Gainsight’s own instance of CS that were visible through the email filter. We have now implemented a fix. We’re evaluating the impact and will share more details as needed.


gunjanm
Forum|alt.badge.img+13
  • Expert ⭐️
  • March 7, 2024

Follow to get an update on the fix. Massive privacy concerns here.


Forum|alt.badge.img
  • Helper ⭐️
  • March 7, 2024

@Kenneth R As part of the impact analysis can you include how long this data was exposed and confirm what types of contacts are included in Gainsight’s instance?


Kenneth R
Forum|alt.badge.img+5
  • Expert ⭐️⭐️
  • March 12, 2024

Hi everyone, following the completion of our internal investigation, we wanted to share an additional follow-up here. As mentioned earlier, contacts from Gainsight customer instances were not exposed. Some contacts from Gainsight’s own instance of CS were visible through the email field's equal filter in the 'Feature Usage' report. Based on our internal logs before we rolled out the fix, a total of 115 requests of the API were made, all by two users from the same company that reported the issue to us. Following the fix that we deployed on Thursday we are immediately taking further steps to prevent this from happening again in the future.