information-disclosure
Safeguard articles tagged "information-disclosure" — guides, analysis, and best practices for software supply chain and application security.
10 articles
Your Feature Flag Targeting Rules Are Visible in the Browser
To evaluate flags locally, the client-side SDK needs the targeting rules: which accounts get the enterprise preview, the pricing tier conditions, the churn-risk exclusions. Open the network panel and anyone can read all of it.
What Your Identifiers Tell the World
A random identifier is not an access control. What identifier design does affect is discovery, inference and what leaks when a URL travels, and a sequential integer in a URL publishes your customer count.
What Leaves Your Application When a User Clicks a Link
The address of the page they were on, and sometimes a handle that lets the destination navigate your tab. Both are defaults, both are one attribute away from fixed, and your URLs contain identifiers and sometimes capabilities.
GraphQL Moved Your Authorisation Checks and Most Teams Left Them Behind
In REST an operation has one endpoint, so the check has one place to live. In a graph a field can be reached by many paths, and a check on the top-level query does not protect the same data reached as a nested field.
Your Health and Metrics Endpoints Describe Your System to Anyone Who Asks
Nobody designed them. A framework, a platform team or a monitoring integration added them, they were configured once, and they are the endpoints that describe your architecture most accurately.
Git Local Clone Information Disclosure via Hardlinks (CVE...
CVE-2022-39253 abuses Git's local clone hardlink optimization to leak files from outside a repository. Here's the impact, fix, and how to stay protected.
Jenkins Arbitrary File Read via Crafted CLI Command (CVE-...
CVE-2018-1999002 let attackers read arbitrary files from Jenkins masters via crafted requests to the Stapler framework, exposing secrets and credentials.
Sensitive Information Exposure in Error Messages
Stack traces, SQL errors, and debug pages routinely leak credentials, paths, and library versions to attackers. Here's how CWE-209 exposure happens and how to close it.
CVE-2023-4641: The shadow-utils Password Leak Explained
CVE-2023-4641 is an information-disclosure flaw in shadow-utils where a failed password change can leave the entered password lingering in memory. Here is who is affected and how to remediate it.
JavaScript Uncaught Exceptions: A Security Guide
A JavaScript uncaught exception is more than a crash — unhandled errors leak internal detail, break security flows midway, and hide attacks. Here is how to handle them safely.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.