-
Notifications
You must be signed in to change notification settings - Fork 12
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Broken link pointing to an unclaimed S3 bucket #2099
Comments
@jairoanaya This was reviewed on staging and can be pushed to prod. Thank you! |
@jairoanaya The broken link also needs to be removed from this branch: https://github.com/GSA/challenges-and-prizes/blob/f90a91565672f1743691fde6210d13a2da0eb6d3/_all-challenges/living-stories-challenge.md |
@jairoanaya Checking in on this ^^^ |
A public facing vulnerability has been identified via the GSA Vulnerability Disclosure Policy.
URL: https://github.com/GSA/challenges-and-prizes
Finding Details: It has been found that a broken link pointing to an unclaimed S3 bucket at https://github.com/GSA/challenges-and-prizes/blob/f90a91565672f1743691fde6210d13a2da0eb6d3/_all-challenges/living-stories-challenge.md
Severity: Low
Steps to reproduce:
Navigate to https://github.com/GSA/challenges-and-prizes/blob/f90a91565672f1743691fde6210d13a2da0eb6d3/_all-challenges/living-stories-challenge.md
Scroll down and observe that a link pointing to the nga-challenge S3 bucket is present:
Clicking the link will open a new tab pointing to a bucket the hacker managed to claim
The text was updated successfully, but these errors were encountered: