Asset Inventory Internal Descriptions are leaked in CSV export

Disclosed: 2023-07-12 06:50:57 By archangel To security
Medium
Vulnerability Details
**Summary:** Hey team, I was looking at the new Asset Inventory functionality and it looks like as a program I can set an Internal asset description ███ This internal description is meant to be private and can't be seen on the scope page: (https://hackerone.com/█████). However, if you export the CSV then it leaks this internal description information **Description:** ### Steps To Reproduce 1. Navigate to https://hackerone.com/██████████ 2. Click the Export to CSV button 3. In the CSV you should see `Internal Description For ES` next to the █████████████ scope item ## Impact Programs are assuming this asset information is indeed internal and may be storing sensitive information such as internal paths/credentials/etc in this description.
Actions
View on HackerOne
Report Stats
  • Report ID: 2011431
  • State: Closed
  • Substate: resolved
  • Upvotes: 66
Share this report