Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Important: Exposed MongoDB cluster in your code

オープン
#49 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
20/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
停滞
技術スタック
mongodb, nodejs

調査の方向性

リポジトリを検索して、露出しているMongoDB URIを見つけ、接続資格情報がどのように読み込まれているかを調査します。issue内の .env と dotenv に関するガイダンスを確認し、その後、GitHubの機密データ削除に関するドキュメントを使ってクリーンアップ手順を決定します。完了の条件は、現在のファイルや履歴で資格情報が公開されておらず、クラスターが保護されていることです。

索引モデルが issue の本文から書いたものです。

説明

[!WARNING]

You have an exposed mongoDB cluster containing multiple databases in this repository.

Hey DSCKGEC, If you receive this issue don't panic, I am a friendly automated script looking around the internet and just to let you know that you have an exposed mongoDB cluster in your code.
I was able to connect and expose those databases from your cluster:
  • accounting
  • calorily
  • gladiapet_sepolia
  • lucid
  • starknetid
  • telepay
  • admin
  • local

A malicious attacker could leak data and get credentials to your or people's services/system, even if you know that no sensible information is stored inside it, it is still very dangerous. I do not know what kind of information your databases hold but a malicious attacker could easily dump all the content, please make sure to follow these steps:

  1. Put your secrets in a .env file
  2. Use a library like dotenv to load the environment variables from your file onto your code
  3. At this point, I would either suggest either using github's tool to erase the history or you could delete the repos on Github, remove the .git folder locally and recreate a new repos with a clean history

In the future make sure to not expose your secrets especially your mongodb uri as it contains your username and password combination. Make sure to create a .env file and load your environment variables into your code accordingly.

If you like what I am doing for the community, please feel free to follow my github account @GaillardTom
主要言語
HTML
スター
9
フォーク
18
PR マージ指標
30日以内にマージされた PR はありません

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

DSCKGEC/Libraryly のほかの issue

DSCKGEC/Libraryly の issue をすべて見る

似ている issue

Backend & API Design の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。