Privates Emails of Moz Workers Leaked in Public file

Disclosed: 2024-09-04 11:36:28 By devil_think To mozilla
None
Vulnerability Details
## Summary: Hi Team in the policy of mozilla emails and names of workers is private and dont be shared or disclosure anyway ! because of this restriction all workers in moz gived id and worker name absoultly crypted .But Its seems that privates emails of moz workers with name and bugs leaked in public files at :https://community.taskcluster-artifacts.net/K5HAOP6RRuuQOQ70LCsf1w/0/public/bugs.json.zst ## Steps To Reproduce: 1. the file is too large to upload like POC but you can download from this link:https://community.taskcluster-artifacts.net/K5HAOP6RRuuQOQ70LCsf1w/0/public/bugs.json.zst 2. exemple of users worker privates emails leaked: ```javascript {"history":[{"when":"1998-09-29T06:05:20Z","changes":[{"removed":"Platform: Rhapsody","added":"XFE","field_name":"component"}],"who":"[email protected]"},{"when":"1998-12-12T17:06:46Z","who":"[email protected]","changes":[{"added":"RESOLVED","field_name":"status","removed":"NEW"},{"added":"WONTFIX","field_name":"resolution","removed":""},{"added":"1998-12-12T17:06:46Z","field_name":"cf_last_resolved","removed":""}]},{"changes":[{"added":"VERIFIED","field_name":"status","removed":"RESOLVED"}],"who":"[email protected]","when":"1999-02-26T20:55:50Z"},{"when":"2004-06-30T02:37:03Z","changes":[{"added":"[email protected]","field_name":"cc","removed":""}],"who":"[email protected]"},{"changes":[{"added":"firstBug","field_name":"alias","removed":""}],"who":"[email protected]","when":"2004-09-22T05:11:42Z"},{"when":"2010-12-08T18:48:57Z","who":"[email protected]","changes":[{"removed":"","field_name":"cc","added":"[email protected]"}]},{"when":"2011-09-13T20:41:18Z","changes":[{"removed":"","added":"686525","field_name":"blocks"}],"who":"[email protected]"},{"changes":[{"field_name":"blocks","added":"","removed":"686525"}],"who":"[email protected]","when":"2011-09-13T20:41:41Z"},{"changes":[{"added":"[email protected]","field_name":"cc","removed":""}],"who":"[email protected]","when":"2013-05-03T17:18:17Z"},{"who":"[email protected]","changes":[{"removed":"","added":"foo","field_name":"whiteboard"}],"when":"2013-07-17T18:25:43Z"},{"when":"2013-07-17T19:01:18Z","changes":[{"removed":"foo","field_name":"whiteboard","added":""}],"who":"[email protected]"},{"changes" ``` ## Impact ## Summary: privates names and emails addresse of mozilla workers leaked
Actions
View on HackerOne
Report Stats
  • Report ID: 2696294
  • State: Closed
  • Substate: informative
  • Upvotes: 49
Share this report