Loading HuntDB...

Sensitive information disclosure on grafana

Low
J
JetBlue
Submitted None
Reported by asce21

Vulnerability Details

Technical details and impact analysis

## Summary: While running through scan I got some endpoints on jetblue subdomains which discloses sensitive information. I know these are out of scope but I think it is necessary to report them ## Steps To Reproduce: 1. Visit the urls in browser `https://████.jetblue.com/metrics` ███ Discloses grafana metrics to unauthorized users ``` https://█████████.jetblue.com/sap/public/info https://████.jetblue.com/sap/public/info ``` ██████ Disclose sensitive information about SAP such as internal IP address and OS `https://███████.travelproducts.jetblue.com/` ███████ aws bucket listing is enabled which discloses sensitive endpoints to unauthorized users ## Impact Unauthorized user can access sensitive info about server resources.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted