The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Additionally the GIT credentials are present and could give unauthorized access to source code repository of private projects.
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044baa2727ab8135b5bbc521bbbf8449cdb
[core] repositoryformatversion = 0 filemode = false bare = false logallrefupdates = true symlinks = false ignorecase = true [remote "origin"] url = https://joemakev2:EKwASsSZEEbQdL2WRRh7@bitbucket.org/npavone/community_dev.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "aa_misc_tasks"] remote = origin merge = refs/heads/aa_misc_tasks [branch "zz_merged__feature_cr359_smartfishingspots_web_v2"] remote = origin merge = refs/heads/feature_cr359_smartfishingspots_web_v2 [branch "zz_pending__hotfix_algolia_community_20jul2023"] remote = origin merge = refs/heads/hotfix_algolia_community_20jul2023 [branch "testing"] remote = origin merge = refs/heads/testing [branch "zz_merged__feature_cr359_smartfishingspots_web_v2__pre_merge"] remote = origin merge = refs/heads/feature_cr359_smartfishingspots_web_v2__pre_merge [branch "feature_cr441_community_search_app"] remote = origin merge = refs/heads/feature_cr441_community_search_app [branch "zz_merged__adjustments_community_chapters_13sep2023"] remote = origin merge = refs/heads/adjustments_community_chapters_13sep2023 [branch "zz_cancelled__adjustments_cr422_setup_flow_new_users_onboarding_comm"] remote = origin merge = refs/heads/adjustments_cr422_setup_flow_new_users_onboarding_comm [branch "feature_cr446_fulfillment_automation_utility"] remote = origin merge = refs/heads/feature_cr446_fulfillment_automation_utility [branch "feature_cr395_chapters_pin_post"] remote = origin merge = refs/heads/feature_cr395_chapters_pin_post [branch "feature_cr359_smartfishingspots_web_v2_auth_restrict_n2"] remote = origin merge = refs/heads/feature_cr359_smartfishingspots_web_v2_auth_restrict_n2 [branch "zz_merged__feature_cr438_comm_new_post_feature"] remote = origin merge = refs/heads/feature_cr438_comm_new_post_feature [branch "zz_merged__bugfix_cr457_sfsv2_issue_shaded_relief"] remote = origin merge = refs/heads/bugfix_cr457_sfsv2_issue_shaded_relief [branch "zz_merged__adjustments_cr460_add_sfsv2_button"] remote = origin merge = refs/heads/adjustments_cr460_add_sfsv2_button [branch "zz_merged__hotfix_cr464_admin_sfs_creation_issue"] remote = origin merge = refs/heads/hotfix_cr464_admin_sfs_creation_issue [branch "staging__pre_merge"] remote = origin merge = refs/heads/staging__pre_merge [branch "staging"] remote = origin merge = refs/heads/staging [branch "zz_merged__adjustments_sfsv2_strikescore_calendar_days_11oct2023"] remote = origin merge = refs/heads/adjustments_sfsv2_strikescore_calendar_days_11oct2023 [branch "zz_merged__feature_cr467_sfsv2_set_user_location_on_load"] remote = origin merge = refs/heads/feature_cr467_sfsv2_set_user_location_on_load [branch "zz_merged__adjustments_cr470_sfsv2_tide_time_positioning"] remote = origin merge = refs/heads/adjustments_cr470_sfsv2_tide_time_positioning [branch "zz_merged__feature_cr466_sfsv2_cache_data_tides_strike_score_weather"] remote = origin merge = refs/heads/feature_cr466_sfsv2_cache_data_tides_strike_score_weather [branch "zz_merged__bugfix_cr473_sfsv2_smartspots_not_loading"] remote = origin merge = refs/heads/bugfix_cr473_sfsv2_smartspots_not_loading [branch "zz_merged__adjustments_sfsv2_retain_date_selection__17oct2023"] remote = origin merge = refs/heads/adjustments_sfsv2_retain_date_selection__17oct2023 [branch "adjustments_cr477_comm_cleanup_db_cache_optimize_table"] remote = origin merge = refs/heads/adjustments_cr477_comm_cleanup_db_cache_optimize_table [branch "staging__tmp_wo_chapter_pin__18oct2023"] remote = origin merge = refs/heads/staging__tmp_wo_chapter_pin__18oct2023 [branch "adjustments_cr480_sfsv2_retain_time_slider_position"] remote = origin merge = refs/heads/adjustments_cr480_sfsv2_retain_time_slider_position [branch "master"] remote = origin merge = refs/heads/master
Severity: high
Fingerprint: 2580fa947178c88602b1737db148c044baa2727ab8135b5bbc521bbb55b736ee
[core] repositoryformatversion = 0 filemode = false bare = false logallrefupdates = true symlinks = false ignorecase = true [remote "origin"] url = https://npavone@bitbucket.org/npavone/community_dev.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master [gui] wmstate = normal geometry = 893x435+78+78 175 196 [branch "staging"] remote = origin merge = refs/heads/staging