Publicly Accessible Administrative Configuration File Exposes Authentication Hashes and Internal Configuration

Disclosed by
JulienZgh
Summary by JulienZgh

Public Disclosure Summary

An unauthenticated administrative configuration file was publicly accessible through the web application. The exposed file disclosed sensitive internal configuration information, including server filesystem paths, CGI endpoints, application template locations, and Unix DES-style authentication password hashes.

The exposed authentication material was sufficient to perform offline password-cracking attempts, and the associated credentials were successfully recovered during security testing. The recovered credentials are not included in this public disclosure.

This issue could allow an unauthenticated attacker to obtain sensitive administrative information, conduct targeted reconnaissance, and potentially compromise administrative functionality if the exposed credentials remain valid.

The vulnerability was reported to NASA through its vulnerability disclosure process, and the sensitive credential material has been intentionally redacted from this public summary.

Activity