Important: Exposed MongoDB cluster in your code
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 20/100
調査の方向性
リポジトリを検索して、露出しているMongoDB URIを見つけ、接続資格情報がどのように読み込まれているかを調査します。issue内の .env と dotenv に関するガイダンスを確認し、その後、GitHubの機密データ削除に関するドキュメントを使ってクリーンアップ手順を決定します。完了の条件は、現在のファイルや履歴で資格情報が公開されておらず、クラスターが保護されていることです。
索引モデルが issue の本文から書いたものです。
説明
[!WARNING]
You have an exposed mongoDB cluster containing multiple databases in this repository.
Hey DSCKGEC, If you receive this issue don't panic, I am a friendly automated script looking around the internet and just to let you know that you have an exposed mongoDB cluster in your code.
I was able to connect and expose those databases from your cluster:
- accounting
- calorily
- gladiapet_sepolia
- lucid
- starknetid
- telepay
- admin
- local
A malicious attacker could leak data and get credentials to your or people's services/system, even if you know that no sensible information is stored inside it, it is still very dangerous. I do not know what kind of information your databases hold but a malicious attacker could easily dump all the content, please make sure to follow these steps:
- Put your secrets in a .env file
- Use a library like dotenv to load the environment variables from your file onto your code
- At this point, I would either suggest either using github's tool to erase the history or you could delete the repos on Github, remove the .git folder locally and recreate a new repos with a clean history
In the future make sure to not expose your secrets especially your mongodb uri as it contains your username and password combination. Make sure to create a .env file and load your environment variables into your code accordingly.
If you like what I am doing for the community, please feel free to follow my github account @GaillardTom
- 主要言語
- HTML
- スター
- 9
- フォーク
- 18
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
DSCKGEC/Libraryly のほかの issue
-
frontend Hard
難易度 3/5 1〜2日 初心者へのやさしさ 35/100
-
frontend Hard
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
-
Backend enhancement Hard KSoC’22
難易度 3/5 1〜2日 初心者へのやさしさ 42/100
-
Backend Easy enhancement KSoC’22
難易度 4/5 3〜5日 初心者へのやさしさ 25/100
-
Backend enhancement Hard
難易度 4/5 3〜5日 初心者へのやさしさ 25/100
DSCKGEC/Libraryly の issue をすべて見る
似ている issue
-
API Bug
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
ProjectSidewalk/SidewalkWebpage#5556 ·
メンテナーはふだん 1 日以内に返信
-
backend::vllm diffusion multimodal
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
openai/openai-agents-python#5229 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
メンテナーはふだん 1 日以内に返信
-
priority/4/normal status/needs-triage type/bug/unconfirmed
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
authelia/authelia#13292 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信