forked from inno-devops-labs/DevSecOps-Intro
-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
Description
Description:
Sensitive data exposure vulnerability found through directory brute-forcing. The file /ftp/acquisitions.md is accessible without authentication and contains confidential information.
Solution:
Implement proper access controls for the /ftp/ directory.
Move confidential documents outside of web-accessible directories.
Reactions are currently unavailable