two aws access key and secret key and database username and password exposed
Critical
Vulnerability Details
## Summary:
hello mozilla security team i found two aws access key and secret key and database username and password exposed in dockerhub image
## Steps To Reproduce:
go to https://hub.docker.com/r/mozilla/commonvoice
and do pull for this image
you will find them in
/code/scripts/test/config.json
███████
poc of the asw keys
████
and also
████
reference
{F3097699}
and the enum for it
████████
## Supporting Material/References
*https://hackerone.com/reports/1720278
* https://hackerone.com/reports/1580567
## Impact
## Summary:
exposure of sensitive data lead to many serious attacks and access
Actions
View on HackerOneReport Stats
- Report ID: 2401648
- State: Closed
- Substate: resolved
- Upvotes: 55