- Status Closed
-
Assigned To
cbay - Private
Attached to Project: Security vulnerabilities
Opened by Bhavish - 12.04.2024
Last edited by cbay - 13.04.2024
Opened by Bhavish - 12.04.2024
Last edited by cbay - 13.04.2024
FS#47 - information disclosure
i found this detial in one of the git file on https://security.alwaysdata.com/.git/config
and this file contains
0000000000000000000000000000000000000000 58bea729f4359a45f69aaba274bb2a931155b427 Cyril Baÿ cbay@alwaysdata.com 1704809861 +0100 clone: from https://github.com/flyspray/flyspray.git
this information in the master named file which i think is sensitive as it disclosing the email address and other stuff also
other files like config and packed-refs contain sensitive information , but its all on you to decide weather the information is sensitive or not
contact me on my email bhavishthakral123@gmail.com
Loading...
Available keyboard shortcuts
- Alt + ⇧ Shift + l Login Dialog / Logout
- Alt + ⇧ Shift + a Add new task
- Alt + ⇧ Shift + m My searches
- Alt + ⇧ Shift + t focus taskid search
Tasklist
- o open selected task
- j move cursor down
- k move cursor up
Task Details
- n Next task
- p Previous task
- Alt + ⇧ Shift + e ↵ Enter Edit this task
- Alt + ⇧ Shift + w watch task
- Alt + ⇧ Shift + y Close Task
Task Editing
- Alt + ⇧ Shift + s save task
Hello,
That information is not sensitive: that's indeed a clone of the public https://github.com/flyspray/flyspray repository.
As for the name (Cyril Baÿ), it's public anyway as I'm one of the owners of alwaysdata, which can be seen on public directories of French companies (e.g. Infogreffe).
Kind regards,
Cyril