Loading HuntDB...

Information Leakage - GitHub - VCenter configuration scripts, StorMagic usernames and password along with default ESXi root password

Medium
U
Uber
Submitted None

Team Summary

Official summary from Uber

@peuch found data exposure on Github - expired passwords and usernames for ESXi (a bare metal hypervisor). The researcher also found credentials to a SendGrid instance (uber_infra_devtools), which would have allowed them to log in to SendGrid and send email from any @uber.com address. However, this would not have given them the ability to see any sensitive Uber data. We enjoyed working with @peuch on this issue and look forward to their future submissions to our program.

Reported by peuch

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$1000.00

Submitted