acikyazilimagi / deprem-yardim-backend-go

Apache License 2.0
288 stars 56 forks source link

vuln: attacker can extract credentials and/or cause a denial of service #115

Closed 0ffffffffh closed 1 year ago

0ffffffffh commented 1 year ago

hi

the backend has a security issue that can lead an attacker extract some creds and/or cause a denial of service. my discord user is "dr.no#1815". if anyone contact me through the discord P.M so i can share the details of the vuln and PoC.

mstrYoda commented 1 year ago

hi

the backend has a security issue that can lead an attacker extract some creds and/or cause a denial of service. my discord user is "dr.no#1815". if anyone contact me through the discord P.M so i can share the details of the vuln and PoC.

Can u write me directly on discord, it might be already fixed but I want to hear details: emre.savci#0226

0ffffffffh commented 1 year ago

i supplied the details, so i'm leaving decision up to you to close the issue.

thanks.

edit: fixed