Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Bitbucket private repo code is exposed !

Naim Bijapure April 5, 2023

We have deployed our code from the bitbucket pipeline to aws ec2. 

recently client received an email from AWS support that the bitbucket code was being exposed. 

anyone from the link can see any files like dotfiles and respective files. 

 

the link looks like this : 

https://bitbucket.org/abcTech/%4sfasdfasdfasdfasdfadddsafasdf%7D/raw/master/apps/api/.env

this is not a real link. but when I click the link that I received it will show all the content from the file even if you are not a Bitbucket user!

 

didn't understand what is happening. what could be the issue? 

my guess is the link is generated from the bitbucket pipeline's artifact but how can it be accessible to anyone? 

 

 

1 answer

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

Post a new question

0 votes
Alex Koxaras _Relational_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
April 5, 2023
TAGS
AUG Leaders

Atlassian Community Events