Data Breaches

Mintlify Data Breach Leads to Exposure of Customer GitHub Tokens

Mintlify announces vulnerability disclosure program after a data breach exposed 91 customer GitHub tokens.

Mintlify announces vulnerability disclosure program after a data breach exposed 91 customer GitHub tokens.

AI-powered code documentation firm Mintlify says customer GitHub tokens were compromised in a data breach caused by a vulnerability in its systems, prompting it to launch a bug bounty program.

Mintlify helps developers generate code documentation. It requires access to the source code, such as GitHub repositories, to analyze it, understand its purpose, and create descriptions.

In an incident notice on its website, the San Francisco-based company says that 91 customer tokens were exposed in a data breach identified on March 1, when it received a report of the issue and discovered unauthorized requests to its servers.

“We noticed that some of these requests targeted sensitive API endpoints and were successful in their attempts. This unusual activity indicated that the actor behind these requests had possession of our private admin access tokens, granting them unauthorized access to our endpoints,” Mintlify says.

After learning that a customer’s repository was accessed using GitHub tokens stored in its database, the company revoked all GitHub token access, rotated administrative access tokens, and hardened the security of its APIs.

“We’ve detected from our logs that 91 GitHub tokens were compromised. The users have been notified, and we’re working with GitHub to identify whether the tokens were used to access private repositories,” Mintlify says.

Mintlify also says that it worked with a bug bounty reporter to address the underlying vulnerability, that it revoked all access tokens again on March 2, and that it is working with cybersecurity firms to investigate the incident and improve its security stance.

It’s unclear if the individual who reported the vulnerability is the one who exploited the flaw. Some ‘bug bounty hunters’ are known to use aggressive tactics, which include exploitation of a bug for what could be interpreted as malicious purposes, to ensure they receive a reward. 

Advertisement. Scroll to continue reading.

To make it easier for security researchers to report vulnerabilities, the company has launched a bug bounty program covering mintlify.com, dashboard.mintlify.com, leaves.mintlify.com, and the Mintlify GitHub apps.

Interested researchers should send vulnerability reports to ‘security @ mintlify.com’. The reports should contain a description of the bug, steps to reproduce, details on the used environment, and proof-of-concept code if possible.

Previously unidentified vulnerabilities with a CVSS score of 4 or higher are guaranteed to receive financial compensation, the company says. Additional information can be found on Mintlify’s responsible disclosure page.

Related: Mercedes Source Code Exposed by Leaked GitHub Token

Related: Major Organizations Using ‘Hugging Face’ AI Tools Put at Risk by Leaked API Tokens

Related: Sourcegraph Discloses Data Breach Following Access Token Leak

Related Content

Cybercrime

Zscaler says its customer, production and corporate environments are not impacted after a notorious hacker offers to sell access.

Ransomware

Philadelphia-based real estate company Brandywine Realty Trust shuts down systems following a ransomware attack.

Data Breaches

University System of Georgia says Social Security numbers and bank account numbers were compromised in the May 2023 MOVEit hack.

Data Breaches

Dropbox says hackers breached its Sign production environment and accessed customer email addresses and hashed passwords. 

Data Breaches

Financial Business and Consumer Solutions (FBCS) says compromised information may include names, dates of birth, Social Security numbers, and account information.

Data Breaches

UnitedHealth confirms that personal and health information was stolen in a ransomware attack that could cost the company up to $1.6 billion.

Data Breaches

The LockBit ransomware gang leaks data allegedly stolen from government contractor Tyler Technologies.

Ransomware

United Nations Development Programme (UNDP) investigating a ransomware attack in which hackers stole sensitive data.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version