Bug Report [critical]

ovix security <[email protected]>
Newsgroups gmane.linux.debian.devel.www
Message-ID <CAKMwnaH02MXY_RD5vDJikB2zh9bcqr5A+cN-X1WdBO5E69McCw@mail.gmail.com>
Hi Team,
I have found a vulnerability in context to publicly accessible Jenkins
dashboard
leaks user/employee data due to asynchPeople people Enabled.

Description:
 Due to the publicly exposed Jenkins Dashboard I was able to see
user/employee data also project data.source code etc etc

Steps to Reproduce :
1) Go to " https://azure-build.debian.net/asynchPeople/ " (Your company
owned)


2) You can see the large list of employee/user data and user id.

Impact:
Sensitive Data Leak publicly
The access also included some source code disclosure

Thank you
Muhammad Danial
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.