Joonas Bergius 1/20/2020

Serious security vulnerability in GunDB (and new ones)

Read Original

The article details the discovery of a serious path traversal vulnerability in the GunDB database, which allowed the author to read any file on the server, including stealing AWS credentials from a public demo instance. It covers the technical details of the exploit, the responsible disclosure process, and the author's critique of the vendor's initial, inadequate response to the security advisory.

Serious security vulnerability in GunDB (and new ones)

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser