Loading HuntDB...

User API Key leakage in Github commit leads to unauthorized access to sql.telemetry.mozilla.org

High
M
Mozilla
Submitted None

Team Summary

Official summary from Mozilla

A Mozilla employee's API token for https://sql.telemetry.mozilla.org was leaked in one of our Github repos. The token provided access to the service dashboard which contained confidential data. The API token was rotated and removed from the service. Note that this asset is out of scope of our program, however, we accepted the report since the reported issue is high.

Reported by anhchangmutrang

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure