Summary by Atlassian
Source code leakage due to exposed sourcemap in Bitbucket Cloud
Source code leakage due to exposed sourcemap in Bitbucket Cloud
I am proceeding the public disclosure of the steps to reproduce and the source code dump.
Bitbucket Cloud including Bitbucket Pipelines (https://bitbucket.org)
Web App
https://bitbucket.org
There is a leakage of source maps due to which entire source code can be dumped from the bitbucket.org site which contains the bitbucket cloud codebase.
You can use Chrome dev tools to list all the files and dump it.
I Have attached the entire source code dump below.