Loading HuntDB...

Development configuration file

Critical
P
Pushwoosh
Submitted None
Reported by protector47

Vulnerability Details

Technical details and impact analysis

Information Disclosure
Hello, I found an **Sensitive Information Disclosure**. A configuration file (e.g. Vagrantfile, Gemfile, Rakefile, ...) was found in this directory. This file may expose sensitive information that could help a malicious user to prepare more advanced attacks. It's recommended to remove or restrict access to this type of files from production systems. #POC https://go.pushwoosh.com/composer.json https://go.pushwoosh.com/composer.lock Open these URLs a configuration file will become download and these files contains very sensitive data. ###IMPACT: These files may disclose sensitive information. This information can be used to launch further attacks. ###PATCH Remove or restrict access to all configuration files accessible from internet. Thanks,

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure