Important: Exposed MongoDB cluster in your code
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 20/100
Hướng nghiên cứu
Tìm kiếm trong repository URI MongoDB bị lộ và kiểm tra cách thông tin xác thực kết nối được tải. Xem lại hướng dẫn về .env và dotenv trong issue, sau đó sử dụng tài liệu của GitHub về việc xóa dữ liệu nhạy cảm để xác định các bước dọn dẹp. Được xem là hoàn tất khi thông tin xác thực không còn bị lộ trong các tệp hiện tại hoặc lịch sử, và cluster được bảo mật.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
[!WARNING]
You have an exposed mongoDB cluster containing multiple databases in this repository.
Hey DSCKGEC, If you receive this issue don't panic, I am a friendly automated script looking around the internet and just to let you know that you have an exposed mongoDB cluster in your code.
I was able to connect and expose those databases from your cluster:
- accounting
- calorily
- gladiapet_sepolia
- lucid
- starknetid
- telepay
- admin
- local
A malicious attacker could leak data and get credentials to your or people's services/system, even if you know that no sensible information is stored inside it, it is still very dangerous. I do not know what kind of information your databases hold but a malicious attacker could easily dump all the content, please make sure to follow these steps:
- Put your secrets in a .env file
- Use a library like dotenv to load the environment variables from your file onto your code
- At this point, I would either suggest either using github's tool to erase the history or you could delete the repos on Github, remove the .git folder locally and recreate a new repos with a clean history
In the future make sure to not expose your secrets especially your mongodb uri as it contains your username and password combination. Make sure to create a .env file and load your environment variables into your code accordingly.
If you like what I am doing for the community, please feel free to follow my github account @GaillardTom
- Ngôn ngữ chính
- HTML
- Star
- 9
- Fork
- 18
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của DSCKGEC/Libraryly
-
frontend Hard
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 35/100
-
DataTable component neededĐang mởfrontend Hard
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
-
Endpoints to filter books neededĐang mởBackend enhancement Hard KSoC’22
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 42/100
-
Backend Easy enhancement KSoC’22
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 25/100
-
Backend enhancement Hard
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 25/100
Tất cả issue của DSCKGEC/Libraryly
Issue tương tự
-
priority: low 🌱 type: enhancement 💅🏼
Độ khó 2/5 Nửa ngày Mức phù hợp với người mới 84/100
nebari-dev/llm-serving-pack#199 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
linebender/parley#849 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
rohitg00/agentmemory#1428 ·
Maintainer thường phản hồi trong vòng 1 ngày