United Nations Security Flaw Exposed 100K Staff Records

  /     /     /  
Publicated : 23/11/2024   Category : security


United Nations Security Flaw Exposed 100K Staff Records


Security researchers have disclosed a vulnerability they exploited to access more than 100,000 private employee records.



Security researchers have disclosed a vulnerability they exploited to access at least 100,000 private records belonging to employees of the United Nations Environmental Programme (UNEP).
Jackson Henry, John Jackson, Nick Sahler, and Aubrey Cottle, a team with security research group Sakura Samurai, discovered the flaw while looking for bugs affecting UN systems, Bleeping Computer reports. They found exposed Git directories and Git credential files on domains connected to both the UNEP and the UN International Labour Organization (ILO); they were able to dump the contents of these files and clone repositories.
The Git directory held sensitive files, including WordPress configuration files containing admin database credentials. These credentials gave the team access to at least 100,000 UN employee records from multiple systems. Exfiltrated data included employee ID, name, employee group, travel justification, start and end dates, approval status, destination, and the length of stay.
Researchers were also able to access more UN databases containing generalized employee records, employee evaluation reports, project funding source records, and human resources demographic data, including nationality, gender, and pay grade, for thousands of UN workers. 
The researchers say the issue has now been addressed. Read the full findings
here
.

Last News

▸ Debunking Machine Learning in Security. ◂
Discovered: 23/12/2024
Category: security

▸ Researchers create BlackForest to gather, link threat data. ◂
Discovered: 23/12/2024
Category: security

▸ Travel agency fined £150,000 for breaking Data Protection Act. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
United Nations Security Flaw Exposed 100K Staff Records