Loading HuntDB...

Forbidden access to https://apps-staging.pingone.com but "/packages.json" visible and full path disclosure

Low
P
Ping Identity
Submitted None

Team Summary

Official summary from Ping Identity

## Summary: If you visit the application https://apps-staging.pingone.com/. The application is protected from unauthorized users (displays Forbidden). In spite of having this protection, an attacker would be able to see the packages information of the application. ## Steps To Reproduce: Go to https://apps-staging.pingone.com/package.json ## Impact This application is only for authorized users. But an attacker can see the package.json of the application, which can be used for further exploitation.

Reported by mjigar821

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$100.00

Submitted

Weakness

Improper Access Control - Generic