Sensitive information disclosure on grafana
Low
J
JetBlue
Submitted None
Actions:
Reported by
asce21
Vulnerability Details
Technical details and impact analysis
## Summary:
While running through scan I got some endpoints on jetblue subdomains which discloses sensitive information. I know these are out of scope but I think it is necessary to report them
## Steps To Reproduce:
1. Visit the urls in browser
`https://████.jetblue.com/metrics`
███
Discloses grafana metrics to unauthorized users
```
https://█████████.jetblue.com/sap/public/info
https://████.jetblue.com/sap/public/info
```
██████
Disclose sensitive information about SAP such as internal IP address and OS
`https://███████.travelproducts.jetblue.com/`
███████
aws bucket listing is enabled which discloses sensitive endpoints to unauthorized users
## Impact
Unauthorized user can access sensitive info about server resources.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved