Loading HuntDB...

Unsecured Dropwizard Admin Panel on display.uber-adsystem.com exposes sensitive server information

Medium
U
Uber
Submitted None

Team Summary

Official summary from Uber

The dropwizard instance running on display.uber-adsystem.com is unsecured, meaning any unauthenticated user can view and use it's admin tools. These tools expose sensitive information on Uber production servers, including the current threads running, info on the CPU, and more server info that should not be exposed. More info on the information exposed through this panel can be seen on dropwizards docs here - https://metrics.dropwizard.io/3.1.0/manual/servlets/#adminservlet

Reported by healdb

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$500.00

Submitted

Weakness

Cleartext Storage of Sensitive Information