Loading HuntDB...

Node modules path disclosure due to lack of error handling

Low
M
Mapbox
Submitted None

Team Summary

Official summary from Mapbox

On May 2nd, 2017 @apapedulimu reported an issue where changing a POST request to a GET request on one of our integration servers returned a full error stack trace rather than an HTTP 404 error. The full error stack trace revealed the full path of the Node.js modules directory on the integration server. We deployed a fix to this issue whereby an HTTP 404 was returned instead.

Reported by apapedulimu

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure