Information Disclosure of Garbage Collection Cycle
Low
Vulnerability Details
Hello,
Upon enumerating a subdomain content I found a directory that discloses the duration of the garbage collection cycles.
I think that these information should be kept private because public should not know information about the target application and how it operates or do its garbage collection process.
##Steps To Reproduce
1. Navigate to the target url: https://gopher.hey.com/metrics
2. See the data.
███
## Impact
This information may help attackers understand more things about the target application which may help in further investigation and exploitation.
Kind Regards.
Actions
View on HackerOneReport Stats
- Report ID: 981796
- State: Closed
- Substate: resolved
- Upvotes: 25