The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652257951003
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/ithena-ai/ithena-itheatre-cms.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Severity: medium
Fingerprint: 2580fa947e78dd08e645819d1e4633dc83269b35e9ca75f1f0e2998a00b34079
HTTP/1.1 200 OK Date: Sat, 06 May 2023 01:28:17 GMT Server: Apache/2.4.29 (Ubuntu) Content-Length: 36 Connection: close Content-Type: text/html; charset=UTF-8 Error more than one connection found[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/ithena-ai/ithena-itheatre-cms.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
SonarQube instance is public and could lead to source code leak.
It may include credentials.
Fingerprint: 589c6afe2f208cfb31766f766dde86786dde86786dde86786dde86786dde8678
Found project: pms-dev Found top file: src/