-
Notifications
You must be signed in to change notification settings - Fork 20
Open
Description
Description
I found an unclaimed s3 bucket was using in file, I claimed the bucket and uploaded poc.
Steps to Reproduce:
- Go to this link to check code
- S3 bucket name: s3.amazonaws.com/navpi-image is using in index.md file

- Click here for POC: https://s3.amazonaws.com/navpi-image/index.html

Fix:
Please remove this S3 bucket from the code or tell me i will delete this bucket from my aws account and claim it.
Impact:
- Attacker can get navcoin employees private IPs Whenever navcoin developers run this project
- Attacker can host malicious content on this bucket
Metadata
Metadata
Assignees
Labels
No labels