DoD internal documents are leaked to the public
Medium
U
U.S. Dept Of Defense
Submitted None
Actions:
Reported by
mrempy
Vulnerability Details
Technical details and impact analysis
Hello Team,
I found a zip file containing documents about DoD. From what I looked at are documents for new soldiers who are starting out, but I didn't just find these files but several others like advice, commander files, plans, certificates and others.
███
██████
█████████
In some of the files I found information such as name, surname, email, phone number and even signatures. Files like these shouldn't be exposed to the public.
██████████
█████████
█████
█████
Here is a list of the folders and documents that exist inside this zip file (it's quite big):
█████
## Impact
* Anyone can download these files and leak them to the public
* Plan something against a specific person for a crime
## System Host(s)
████
## Affected Product(s) and Version(s)
## CVE Numbers
## Steps to Reproduce
1. Open in your browser the URL https://█████
2. Look for the file called "████" and download it
3. Extract the file and look at the documents
I found some certificates in the Formats folder, in the Welcome folder there is someone's phone number, command files are in the Commander Files folder.
## Suggested Mitigation/Remediation Actions
* Change the location of this zip file and the others
* Block viewing of files in this folder
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure