The following URL is publicly accessible and is leaking source code : https://18.198.157.0/.git/config
Additionally the GIT credentials are present and could give unauthorized access to source code repository of private projects.
[fetch]
recurseSubmodules = false
[core]
repositoryformatversion = 0
filemode = true
bare = false
logallrefupdates = true
[remote "origin"]
url = https://gitlab-ci-token:<redacted>@gitlab.ringl.im/ringl/server-app/b2b-console.git
fetch = +refs/heads/*:refs/remotes/origin/*
[fetch]
recurseSubmodules = false
[core]
repositoryformatversion = 0
filemode = true
bare = false
logallrefupdates = true
[remote "origin"]
url = https://gitlab-ci-token:<redacted>@gitlab.ringl.im/ringl/server-app/b2b-console.git
fetch = +refs/heads/*:refs/remotes/origin/*
[fetch]
recurseSubmodules = false
[core]
repositoryformatversion = 0
filemode = true
bare = false
logallrefupdates = true
[remote "origin"]
url = https://gitlab-ci-token:<redacted>f@gitlab.ringl.im/ringl/server-app/b2b-console.git
fetch = +refs/heads/*:refs/remotes/origin/*
bip! I'm a LeakIX probe. This issue looks like it has been resolved!