Loading HuntDB...

Information Leak - Github - JMS Information

High
S
Starbucks
Submitted None
Reported by peuch

Vulnerability Details

Technical details and impact analysis

Information Disclosure
Hi, After some research, I found a leak on GitHub that might lead to accessing sensitive data of employees or clients (not sure based on the code). There is also a SAP S-user to access a cloud based HANA service. I have not confirmed what kind of data is in there to avoid potential legal issues. I will let you guys figure that out ;) I am not sure who is the owner of the repository, but I can tell you that the SAP credentials are for someone at Starbucks China. https://github.com/karaskay/personalware Some interesting files: https://github.com/karaskay/personalware/blob/989723f896eec67a50a9b9f59ceefc48a046049b/python/PycharmProjects/JMS36/testhttprequestjson.py (SAP Cloud HANA credentials) https://github.com/karaskay/personalware/blob/989723f896eec67a50a9b9f59ceefc48a046049b/python/PycharmProjects/JMS36/JMSproducerforsurvey.py (starbuckstest domain credentials) Thanks! ## Impact High potential of an unauthorized access to PII data

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure