credentials found in config file on github

Disclosed: 2021-04-28 16:32:58 By akitech To blockfi
Low
Vulnerability Details
## Summary: Hi, credentials belonging to blockfi.com was found exposed on github, these credentials can lead to attackers gaining access into the network and stealing information and destroying servers ## Steps To Reproduce: https://github.com/paw2py/ETH_API/blob/8658c39d1742f07ac7b5f0e41b82ad164f3ba099/config.py https://github.com/naboagye-blockfi/ecs-pipeline/blob/38b1417d4dfff624eb6f649d27256758f395aa65/COPY/prometheus/prometheus.yml ## Supporting Material/References: [list any additional material (e.g. screenshots, logs, etc.)] * [attachment / reference] ## Impact these credentials can lead to attackers gaining access into the network and stealing information and destroying servers
Actions
View on HackerOne
Report Stats
  • Report ID: 1134060
  • State: Closed
  • Substate: resolved
  • Upvotes: 46
Share this report