The email addresses of 76,000 Mozilla Developer Network (MDN) members and 4,000 passwords have become publicly available due to mismanagement by the company.
The Mozilla Foundation issued a warning about the incident, stating that they were notified by a web developer around June 23 that a data sanitization flaw caused sensitive information to be exposed.
It appears that the bug persisted for a period of 30 days, and when Mozilla managed to locate the leak point, it immediately disabled the process in order to stop the data leak.
"While we did not detect any malicious activity on this server, we cannot be certain that such access did not occur," the company said in a blog post by Stormy Peters, Director of Developer Services.
The passwords were encrypted and salted hashes, meaning they couldn't be used to log in to the Mozilla Developer Network website by malicious users. However, the email addresses could be used to send spam.
All users affected by the incident have been notified of the accidental leak to change their passwords.
Source: secnews.gr
