Skip to content

bug: Risk of leaking the scan result files #1202

@confd0

Description

@confd0

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

The huntr.com link for reNgine is down, and email is not responsed. so I put it here.
image

I just install reNgine v2.0.3 and find a nginx config file: https://github.com/yogeshojha/rengine/blob/f362189c9b253fd38c7c17c08e5cfc87aee0bfaf/config/nginx/rengine.conf

image

look like I can read any scan results file from other rengine site if I know the file names, and the files names can be brute force:

image

Expected Behavior

non-login user should not have privilege to read scan result files

Steps To Reproduce

brute force https://rengine_example.com/media/<domain>_<int>/subdomains_sublister.txt , change <domain> and <int> to fuzz.

Environment

- reNgine: 2.0.3
- OS: Linux
- Python: 
- Docker Engine: 
- Docker Compose: 
- Browser:

Anything else?

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    SecuritySecurity related issuesbugSomething isn't workingtop-priority

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions