information disclosure
None
C
curl
Submitted None
Actions:
Reported by
rono_07
Vulnerability Details
Technical details and impact analysis
## Summary:
web.archive.org -website
web. Archive is a website like google search, but he saves all links. Wayback disclosing URL's without users' permission,
Anyone can access them maybe (emails and passwords) they are notes they should be private and see everything
just by searching about random notes
and it doesn't work like that , its should be:
only people who i want them to see my notes can access them
not any random people find my notes on web.archive.org/
url : https://web.archive.org/web/*/https://github.com/curl/curl*
url : https://web.archive.org/web/*/https://curl.se*
Fix:
block web.archive.org from disclose your websites.
so i really hope you will review that and fix it to keep your users safe because they maybe save emails or passwords or company information's and they want to share them only with company employers, i will wait an update from you :)
## Impact
attacker can access notes without permission
Report Details
Additional information and metadata
State
Closed
Substate
Not-Applicable