Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1.
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
Link | Tags |
---|---|
https://huntr.dev/bounties/2628431e-6a98-4063-a0e3-a8b1d9ebaa9c | exploit third party advisory patch |
https://github.com/chocobozzz/peertube/commit/0c058f256a195b92f124be10109c95d1fbe93ad8 | third party advisory patch |