Loading HuntDB...

Mozilla FuzzManager API Token Exposed in Git Commit

Critical
M
Mozilla
Submitted None

Team Summary

Official summary from Mozilla

The researcher has discovered that an API token for the FuzzManager of Mozilla (https://fuzzmanager.fuzzing.mozilla.org) was leaked in one of our GitHub repositories. The API token provides access to our internal fuzzing data and results. The token was accidentally configured with read-write access, we rotated the tokens and made sure to use write-only tokens in our workers

Reported by yakirka

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Cleartext Storage of Sensitive Information