Code Repository

  • CWE 425
  • WASC 34

Code repository was found in this folder. An attacker can extract sensitive information by requesting the hidden metadata directory that version control tool creates. The metadata directories are used for development purposes to keep track of development changes to a set of source code before it is committed back to a central repository (and vice-versa).

Remediation

Remove the repository from production systems or restrict (or password protect) access to it.

References