Opened 3 years ago

Closed 3 years ago

#63626 closed defect (invalid)

Security Vulnerability

Reported by: raunak2136 Owned by:
Priority: High Milestone:
Component: website Version:
Keywords: Cc:
Port:

Description

While doing Recon on macports.org I found a website that is when opened leaking a lot of data belonging to macports.org which can lead to the disclosure of sensitive information

Website- http://packages.macports.org/

Am attaching the Screenshots for better understanding

https://trac.macports.org/attachment/wiki/WikiFormatting/Screenshot_256.png

This is a bit serious and concerning issue, if the data is being leaked like that both for the company and its users, so the right measures should be taken as soon as possible

Regards,

Raunak Singhvi

Attachments (1)

Screenshot_256.png (73.0 KB) - added by raunak2136 3 years ago.

Download all attachments as: .zip

Change History (2)

Changed 3 years ago by raunak2136

Attachment: Screenshot_256.png added

comment:1 Changed 3 years ago by jmroot (Joshua Root)

Resolution: invalid
Status: newclosed

Thank you for your concern and the report, however there is no sensitive information on packages.macports.org. It serves software packages to the public, which is what the directories shown in your screenshot contain. If you believe there is other, inappropriate information being disclosed, please send the details to admin@….

Note: See TracTickets for help on using tickets.