HospitalRun / hospitalrun-dblisteners

CouchDB listeners for HospitalRun
GNU General Public License v3.0
20 stars 41 forks source link

Sensitive Server Side information Disclosure #6

Closed sanjogpandasp closed 7 years ago

sanjogpandasp commented 7 years ago

Hi,

There is a sensitive information disclosure which reflects DB and system logs.

Try to browse to https://beta.hospitalrun.io/db/config/_changes

jkleinsc commented 7 years ago

@sanjogpandasp thanks for this information. I am in process on a fix.

jkleinsc commented 7 years ago

@sanjogpandasp I have updated the couch initialization scripts to disallow changing the config db, so I am going to close this issue. Thank you for reporting this.