Accidental release of internal passwords, & API tokens for the Crossref system

Geoffrey Bilder · 2019

TL;DR On Wednesday, October 2nd, 2019 we discovered that we had accidentally pushed the main Crossref system as part of a docker image into a developer's account on Docker Hub. The binaries and configuration files that made up the docker image included embedded passwords and API tokens that could have been used to compromise our systems and infrastructure.

Read the paper · More papers on PaperTik