Information Leakage - GitHub - VCenter configuration scripts, StorMagic usernames and password along with default ESXi root password
Medium
U
Uber
Submitted None
Team Summary
Official summary from Uber
@peuch found data exposure on Github - expired passwords and usernames for ESXi (a bare metal hypervisor). The researcher also found credentials to a SendGrid instance (uber_infra_devtools), which would have allowed them to log in to SendGrid and send email from any @uber.com address. However, this would not have given them the ability to see any sensitive Uber data. We enjoyed working with @peuch on this issue and look forward to their future submissions to our program.
Actions:
Reported by
peuch
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$1000.00