The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522266ead3a
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@bitbucket.org:ortodonticcenter/franqueadora.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master [branch "OCSCRUM-5314-franqueadora---adicionar-ca"] remote = origin merge = refs/heads/OCSCRUM-5314-franqueadora---adicionar-ca
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522266ead3a
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@bitbucket.org:ortodonticcenter/franqueadora.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master [branch "OCSCRUM-5314-franqueadora---adicionar-ca"] remote = origin merge = refs/heads/OCSCRUM-5314-franqueadora---adicionar-ca
Open service 15.229.101.43:443 ยท cobaas-api.btgpactual.com
2025-12-23 00:17
HTTP/1.1 403 Forbidden
Date: Tue, 23 Dec 2025 00:17:11 GMT
Content-Type: application/json
Content-Length: 23
Connection: close
x-amzn-RequestId: 029357a5-168d-43cc-81c8-ac1eae30e8e7
Access-Control-Allow-Origin: *
Access-Control-Allow-Headers: Content-Type,X-Amz-Date,Authorization,X-Api-Key,X-Amz-Security-Token,Channel,RootContract,Username
x-amzn-ErrorType: ForbiddenException
x-amz-apigw-id: WA_dRHs1mjQESiQ=
Access-Control-Allow-Methods: DELETE,GET,HEAD,OPTIONS,PATCH,POST,PUT
{"message":"Forbidden"}