Unsecured Dropwizard Admin Panel on display.uber-adsystem.com exposes sensitive server information
Medium
U
Uber
Submitted None
Team Summary
Official summary from Uber
The dropwizard instance running on display.uber-adsystem.com is unsecured, meaning any unauthenticated user can view and use it's admin tools. These tools expose sensitive information on Uber production servers, including the current threads running, info on the CPU, and more server info that should not be exposed. More info on the information exposed through this panel can be seen on dropwizards docs here - https://metrics.dropwizard.io/3.1.0/manual/servlets/#adminservlet
Actions:
Reported by
healdb
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$500.00
Submitted
Weakness
Cleartext Storage of Sensitive Information