Information Disclosure of Garbage Collection Cycle

Disclosed: 2020-11-04 19:09:20 By ahmd_halabi To basecamp
Low
Vulnerability Details
Hello, Upon enumerating a subdomain content I found a directory that discloses the duration of the garbage collection cycles. I think that these information should be kept private because public should not know information about the target application and how it operates or do its garbage collection process. ##Steps To Reproduce 1. Navigate to the target url: https://gopher.hey.com/metrics 2. See the data. ███ ## Impact This information may help attackers understand more things about the target application which may help in further investigation and exploitation. Kind Regards.
Actions
View on HackerOne
Report Stats
  • Report ID: 981796
  • State: Closed
  • Substate: resolved
  • Upvotes: 25
Share this report