Exposed .git Folders in Public S3 Buckets Can Leak Entire Source Code Histories
A vulnerability disclosed via HackerOne (report #2383486) showed that Mozilla accidentally uploaded its .git/ directory alongside marketing content to a public AWS S3 bucket. Because the deployment pipeline used git clone rather than a clean export, the entire repository metadata — including commit history, developer emails, and git remote URLs — was publicly accessible. Attackers can reconstruct the full repository, including secrets that were previously deleted from later commits, using just three shell commands. The root cause is a mismatch between developer intent and pipeline behavior: aws s3 sync uploads everything in the build directory, not just the intended build output. The fix is straightforward — either delete the .git/ folder before syncing or use git archive, which exports only tracked file content without repository metadata.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in