Sensitive information disclosure on grafana

Disclosed: 2024-02-26 22:02:26 By asce21 To jetblue
Low
Vulnerability Details
## Summary: While running through scan I got some endpoints on jetblue subdomains which discloses sensitive information. I know these are out of scope but I think it is necessary to report them ## Steps To Reproduce: 1. Visit the urls in browser `https://████.jetblue.com/metrics` ███ Discloses grafana metrics to unauthorized users ``` https://█████████.jetblue.com/sap/public/info https://████.jetblue.com/sap/public/info ``` ██████ Disclose sensitive information about SAP such as internal IP address and OS `https://███████.travelproducts.jetblue.com/` ███████ aws bucket listing is enabled which discloses sensitive endpoints to unauthorized users ## Impact Unauthorized user can access sensitive info about server resources.
Actions
View on HackerOne
Report Stats
  • Report ID: 1448218
  • State: Closed
  • Substate: resolved
  • Upvotes: 41
Share this report