[mena.starbucks.com] Laravel App Log & Configuration Disclosure.
High
S
Starbucks
Submitted None
Team Summary
Official summary from Starbucks
bobrov discovered a misconfiguration in a Laravel instance at mena.starbucks.com, which exposed log files and environment variables containing database management credentials. The logs have been removed, and the instance of Laravel has been disabled. Thank you @bobrov for finding this misconfiguration and helping to resolve this issue!
Actions:
Reported by
bobrov
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure