JDBC credentials leaked via github

Disclosed: 2020-07-27 16:44:01 By walidhossain010 To yelp
None
Vulnerability Details
## Summary: jdbc credentials found on a public github repo.though the repo belongs to yelp or not there is a doubt.I have found many more sensitive data on that repo.so kindly check the repo all together.sensitive data found publicly. ## Platform(s) Affected: website ## Steps To Reproduce: 1. visit the link ```https://github.com/supernebula/yelp-j/blob/36de49095d7f3221e3a50adf9bd7ab26ef585f24/yelp/yelp-web-search/src/main/resources/application-dev.properties ``` you will see leaked credentials.also visit other path to discover more sensitive info. ## Impact private credentials disclosure.
Actions
View on HackerOne
Report Stats
  • Report ID: 935573
  • State: Closed
  • Substate: informative
  • Upvotes: 3
Share this report