Potential leak of server side software at repogohi.nordvpn.com

Disclosed: 2020-02-16 18:51:39 By zerody To nordsecurity
Medium
Vulnerability Details
## Summary: I found a public Git Repository at https://repogohi.nordvpn.com/. It looks like the software components in this repository are part of the VPN Servers. So I'm afraid there's a certain risk. The following packages are among others publicly available: ``` openvpn-xor_2.4.5-stretch1nord_amd64.deb openvpn_2.4.5-stretch1nord_amd64.deb squid-langpack-nord_20180226-1_all.deb ``` Furthermore I found the Origin-IP (behind Cloudflare): https://95.216.8.4/ This allows an attacker to bypass all security features of Cloudflare. Feel free to correct my assumption and Severity of this report :) ## Impact - Leak of server side software components (VPN Infrastructure) - Simplifies the reengineering of the used software
Actions
View on HackerOne
Report Stats
  • Report ID: 756182
  • State: Closed
  • Substate: resolved
  • Upvotes: 51
Share this report