Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bug #2277

Open
ahmed23132 opened this issue Nov 25, 2024 · 2 comments
Open

bug #2277

ahmed23132 opened this issue Nov 25, 2024 · 2 comments

Comments

@ahmed23132
Copy link

Dear GitHub Security Team,

I would like to report a security incident involving a public repository that contains sensitive information.

Repository Information:

Repository URL: https://github.com/hubrix/arcamens/blob/0d8dc839d0840532cbeb811320e161b881715376/NOTES.md?plain=1#L4
Repository Owner: [Insert repository owner's username or organization name]
Commit/Branch: [Provide commit hash or branch name where the information was found, if possible]

Description of the Issue: In the aforementioned repository, I found sensitive data that should not have been made public. Specifically, I came across PayPal sandbox account credentials (email and password), which could potentially be used to access accounts in the PayPal sandbox environment.

The credentials found are as follows:

PayPal Buyer Email: [email protected]
Password: Lv8JDFEc
PayPal Merchant Email: [email protected]
Password: Lv8JDFEc

This is a significant security risk as it exposes sensitive account credentials in a public space. I believe this information should be removed immediately to prevent any potential misuse.

Steps Taken: I have not attempted to access any account or use the provided credentials in any way. I am reporting this issue to ensure it is handled appropriately.

Action Requested: Please investigate this issue and remove any sensitive information from the repository to prevent any potential misuse.

Attached Screenshot:

poc من بينات حساسه ف ريبو

Thank you for your prompt attention to this matter.

Sincerely :Ahmed Ali
Email Address :[email protected]

@github-actions github-actions bot changed the title Security Incident Report - Sensitive Information Leaked [DOCS-714] Security Incident Report - Sensitive Information Leaked Nov 25, 2024
Copy link
Contributor

github-actions bot commented Nov 25, 2024

Internal Jira issue: DOCS-714

@ahmed23132 ahmed23132 changed the title [DOCS-714] Security Incident Report - Sensitive Information Leaked bug Nov 25, 2024
@ahmed23132
Copy link
Author

ahmed23132 commented Nov 25, 2024

ok don

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant