Loading HuntDB...

[experience.uber.com] Node.js source code disclosure & anonymous access to internal Uber documents, templates and tools

Medium
U
Uber
Submitted None

Team Summary

Official summary from Uber

A configuration file on experience.uber.com exposed details for the server configuration as well as information about the content hosted on the site. The site itself did require authentication to log in, but this config file was publicly accessible. Other accessible URLs included slide deck templates and a document on platform design.

Reported by molejarka

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure