Important: Exposed MongoDB cluster in your code
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 25/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- javascript, mongodb
Research direction
No file or test is named. Search the repository and Git history for the MongoDB URI, then review the connection code and exposed databases listed in the report. Done means the credentials are rotated, the secret is no longer present in current files or history, and the application loads it through environment variables as described.
Written by the indexing model from the issue text.
Description
[!WARNING]
You have an exposed mongoDB cluster containing multiple databases in this repository.
Hey BuildForSDG, If you receive this issue don't panic, I am a friendly automated script looking around the internet and just to let you know that you have an exposed mongoDB cluster in your code.
I was able to connect and expose those databases from your cluster:
- CountryCity
- sample_mflix
- admin
- local
A malicious attacker could leak data and get credentials to your or people's services/system, even if you know that no sensible information is stored inside it, it is still very dangerous. I do not know what kind of information your databases hold but a malicious attacker could easily dump all the content, please make sure to follow these steps:
- Put your secrets in a .env file
- Use a library like dotenv to load the environment variables from your file onto your code
- At this point, I would either suggest either using github's tool to erase the history or you could delete the repos on Github, remove the .git folder locally and recreate a new repos with a clean history
In the future make sure to not expose your secrets especially your mongodb uri as it contains your username and password combination. Make sure to create a .env file and load your environment variables into your code accordingly.
If you like what I am doing for the community, please feel free to follow my github account @GaillardTom
- Dominant language
- JavaScript
- Stars
- 2
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from BuildForSDG/GoBusiness
-
enhancement
Difficulty 5/5 Over a week Newbie friendliness 15/100
BuildForSDG/GoBusiness#10 ·
-
enhancement
Difficulty 4/5 3-5 days Newbie friendliness 25/100
All issues in BuildForSDG/GoBusiness
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 3 days
-
Add: Atlas TVOpenchannels:add check:passed
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
Maintainers usually reply within 4 days
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
jaegertracing/jaeger-ui#4547 · 3 comments ·
Maintainers usually reply within 1 day
-
feedback simulation workshop
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
githubnext/gh-aw-workshop#4090 ·
Maintainers usually reply within 1 day
-
bug deck: add to staging level: missing p-feature: Manage Submissions p-feature: Submissions and process priority: MUST HAVE ready for dev lead role: missing size: missing time sensitive
Difficulty 2/5 1-3 hours Newbie friendliness 67/100
hackforla/tdm-calculator#3581 ·
Maintainers usually reply within 2 days