-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Description
In the file [auto_sizing/targets.py]
(
auto-sizing/auto_sizing/targets.py
Line 145 in 098495e
| from_expr="mozdata.org_mozilla_ios_firefox.baseline_clients_daily", |
from_expr="`moz-fx-data-shared-prod.org_mozilla_ios_firefox.baseline_clients_first_seen`"
The string moz-fx-data-shared-prod.org looks like a real domain, and in fact:
The domain [moz-fx-data-shared-prod.org]
(https://www.namecheap.com/domains/registration/results/?domain=moz-fx-data-shared-prod.org) is currently available for registration on Namecheap.
This is not a security vulnerability, but a naming confusion risk:
Contributors may mistakenly search for documentation at moz-fx-data-shared-prod.org.
Creates a very weak social engineering vector (e.g., manual phishing if someone visits the domain).

Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels