Mercedes-Benz accidentally leaks its own source code via GitHub

Spread the love

Car manufacturer Mercedes-Benz accidentally leaked its own source code via GitHub. This was because an employee’s GitHub token had ended up in a public repository. The token has now been revoked and the repository is offline.

The flaw was discovered this month by security researcher Shubham Mittal, that news site TechCrunch informed. According to Mittal, the token could give anyone unlimited access to Mercedes’ GitHub Enterprise Server. It contains, among other things, important documents, source code and passwords of the car manufacturer, writes Techcrunch based on the evidence provided by Mittal. It is unknown whether any customer data was present in the repository.

TechCrunch reported the leak to Mercedes-Benz on Monday. On Wednesday, a spokesperson confirmed to the site that the token had been revoked and the repository taken offline. According to the company, it was a human error and an investigation into the leak is underway. It is not yet clear whether the leak has been discovered by other parties.

You might also like