I Ran a Security Scanner Against Mastodon, Discourse, and Chatwoot's AWS Defaults. He
I used Stave, an open-source configuration safety tool, to answer those questions for three of the most popular open-source Rails applications: Mastodon (47K stars), Discourse (43K stars), and Chatwoot (22K stars).
The results: 47 security findings across three projects. Two of the three default to publicly readable S3 buckets. None configure encryption, access logging, or Public Access Block.
This isn’t a vulnerability disclosure. These projects work exactly as documented. The problem is the documentation. Full details:
Post a comment