BugCrowd Bug Bounty Disclosure: P5 – Sensitive NASA Equipment Inventory Disclosed via Public Endpoint on www3.nasa.gov – candykhaba

Sensitive NASA Equipment Inventory Disclosed via Public Endpoint on www3.nasa.gov

Sensitive NASA Equipment Inventory Disclosed via Public Endpoint on www3.nasa.gov

Researcher: candykhaba
Engagement: National Aeronautics and Space Administration (NASA) – Vulnerability Disclosure Program
Disclosed at: 2025-06-16T19:39:33Z
Priority: P5
Status: Resolved

Summary

An unauthenticated endpoint on www3.nasa.gov is disclosing a lot of sensitive asset inventory lists that contains 115 page.

Activity Feed

Actor Details Timestamp (UTC)
Martin_NASA Martin_NASA published 2025-06-16T19:39:33Z
candykhaba candykhaba updated 2025-06-16T17:04:03Z
candykhaba candykhaba requested 2025-06-16T16:55:19Z
Brandon Brandon changed the state to to resolved 2025-06-16T15:54:05Z
Brandon Brandon changed the severity to 2025-06-16T15:54:03Z
Brandon Brandon sent a: message 2025-06-16T15:53:54Z
Brandon Brandon changed the state to to informational 2025-06-16T15:51:16Z
Martin_NASA Martin_NASA changed the state to to unresolved 2025-06-13T20:42:57Z
viper-bugcrowd viper-bugcrowd changed the state to to triaged 2025-06-10T08:42:37Z
viper-bugcrowd viper-bugcrowd sent a: message 2025-06-10T08:42:33Z
candykhaba candykhaba created the submission 2025-06-10T08:12:19Z

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.