Hello,
Our client received an email today from a security company stating that we have a serious security issue. As proof that the vulnerability is valid they included a valid tree and parent ID / commit ID as well as the author name and email from our private Bitbucket repository.
I double checked that our repository is indeed set to private. I spoke with the hosting company to confirm they do not see anything malicious on their end. If I try to view the /.git folder by directly typing it in the url I receive a 404 error.
My question is, how were they able to obtain those details from our private Bitbucket repository and what should I do to ensure our repository and website are secure?
Thanks!