Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Important: Exposed MongoDB cluster in your code

Aperta
#49 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
20/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Ferma
Stack tecnologico
mongodb, nodejs

Direzione di ricerca

Cerca nel repository l’URI MongoDB esposta e verifica come vengono caricate le credenziali di connessione. Esamina le indicazioni su .env e dotenv nell’issue, quindi usa la documentazione di GitHub sulla rimozione dei dati sensibili per determinare i passaggi di pulizia. Il lavoro è completato quando le credenziali non sono più esposte nei file correnti né nella cronologia e il cluster è protetto.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

[!WARNING]

You have an exposed mongoDB cluster containing multiple databases in this repository.

Hey DSCKGEC, If you receive this issue don't panic, I am a friendly automated script looking around the internet and just to let you know that you have an exposed mongoDB cluster in your code.
I was able to connect and expose those databases from your cluster:
  • accounting
  • calorily
  • gladiapet_sepolia
  • lucid
  • starknetid
  • telepay
  • admin
  • local

A malicious attacker could leak data and get credentials to your or people's services/system, even if you know that no sensible information is stored inside it, it is still very dangerous. I do not know what kind of information your databases hold but a malicious attacker could easily dump all the content, please make sure to follow these steps:

  1. Put your secrets in a .env file
  2. Use a library like dotenv to load the environment variables from your file onto your code
  3. At this point, I would either suggest either using github's tool to erase the history or you could delete the repos on Github, remove the .git folder locally and recreate a new repos with a clean history

In the future make sure to not expose your secrets especially your mongodb uri as it contains your username and password combination. Make sure to create a .env file and load your environment variables into your code accordingly.

If you like what I am doing for the community, please feel free to follow my github account @GaillardTom
Lingua principale
HTML
Stelle
9
Fork
18
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di DSCKGEC/Libraryly

Tutte le issue di DSCKGEC/Libraryly

Issue simili

Altre issue su Backend & API Design

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.