Node modules path disclosure due to lack of error handling
Low
M
Mapbox
Submitted None
Team Summary
Official summary from Mapbox
On May 2nd, 2017 @apapedulimu reported an issue where changing a POST request to a GET request on one of our integration servers returned a full error stack trace rather than an HTTP 404 error. The full error stack trace revealed the full path of the Node.js modules directory on the integration server. We deployed a fix to this issue whereby an HTTP 404 was returned instead.
Actions:
Reported by
apapedulimu
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure