Development configuration file
Critical
P
Pushwoosh
Submitted None
Actions:
Reported by
protector47
Vulnerability Details
Technical details and impact analysis
Hello,
I found an **Sensitive Information Disclosure**.
A configuration file (e.g. Vagrantfile, Gemfile, Rakefile, ...) was found in this directory. This file may expose sensitive information that could help a malicious user to prepare more advanced attacks. It's recommended to remove or restrict access to this type of files from production systems.
#POC
https://go.pushwoosh.com/composer.json
https://go.pushwoosh.com/composer.lock
Open these URLs a configuration file will become download and these files contains very sensitive data.
###IMPACT:
These files may disclose sensitive information. This information can be used to launch further attacks.
###PATCH
Remove or restrict access to all configuration files accessible from internet.
Thanks,
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure