JDBC credentials leaked via github
None
Y
Yelp
Submitted None
Actions:
Reported by
walidhossain010
Vulnerability Details
Technical details and impact analysis
## Summary:
jdbc credentials found on a public github repo.though the repo belongs to yelp or not there is a doubt.I have found many more sensitive data on that repo.so kindly check the repo all together.sensitive data found publicly.
## Platform(s) Affected:
website
## Steps To Reproduce:
1. visit the link
```https://github.com/supernebula/yelp-j/blob/36de49095d7f3221e3a50adf9bd7ab26ef585f24/yelp/yelp-web-search/src/main/resources/application-dev.properties
```
you will see leaked credentials.also visit other path to discover more sensitive info.
## Impact
private credentials disclosure.
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Information Disclosure