Access to Glassdoor's Infra (AWS) and BitBucket account through leaked repo
Critical
G
Glassdoor
Submitted None
Team Summary
Official summary from Glassdoor
AWS credentials associated to a Glassdoor employee was exposed via publicly accessible repo. This keys gave access to a particular account on AWS related to big data. We have removed and rotated the keys since and corrected the permissions on the repo. Thanks @prateek_0490 for detecting and letting us know the issue out here.
Actions:
Reported by
prateek_0490
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure