Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Important: Exposed MongoDB cluster in your code

未关闭
#49 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
20/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
停滞
技术栈
mongodb, nodejs

调研方向

在仓库中搜索已暴露的 MongoDB URI,并检查连接凭据是如何加载的。查看 issue 中关于 .env 和 dotenv 的指导,然后使用 GitHub 关于移除敏感数据的文档来确定清理步骤。完成的标准是凭据不再暴露在当前文件或历史记录中,并且集群已得到保护。

由索引模型根据 Issue 内容生成。

描述

[!WARNING]

You have an exposed mongoDB cluster containing multiple databases in this repository.

Hey DSCKGEC, If you receive this issue don't panic, I am a friendly automated script looking around the internet and just to let you know that you have an exposed mongoDB cluster in your code.
I was able to connect and expose those databases from your cluster:
  • accounting
  • calorily
  • gladiapet_sepolia
  • lucid
  • starknetid
  • telepay
  • admin
  • local

A malicious attacker could leak data and get credentials to your or people's services/system, even if you know that no sensible information is stored inside it, it is still very dangerous. I do not know what kind of information your databases hold but a malicious attacker could easily dump all the content, please make sure to follow these steps:

  1. Put your secrets in a .env file
  2. Use a library like dotenv to load the environment variables from your file onto your code
  3. At this point, I would either suggest either using github's tool to erase the history or you could delete the repos on Github, remove the .git folder locally and recreate a new repos with a clean history

In the future make sure to not expose your secrets especially your mongodb uri as it contains your username and password combination. Make sure to create a .env file and load your environment variables into your code accordingly.

If you like what I am doing for the community, please feel free to follow my github account @GaillardTom
主要语言
HTML
星标
9
派生
18
PR 合并指标
30 天内没有已合并 PR

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

DSCKGEC/Libraryly 的其他 Issue

查看 DSCKGEC/Libraryly 的全部 Issue

相似的 Issue

更多 Backend & API Design Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。