# Plugin Portal Potential Data Exposure

DevFeed: [Plugin Portal Potential Data Exposure](<https://devfeed.tech/articles/plugin-portal-potential-data-exposure-24681.md>)

Original publisher: [Read original article](<https://blog.gradle.org/portal-information-exposure>)

Author: Louis Jacomet

Published: 2022-08-24T04:00:00Z

Content type: news

Language: en

Sources: [The Gradle Blog](<https://devfeed.tech/sources/the-gradle-blog.md>)

Topics: [Gradle](<https://devfeed.tech/topics/gradle.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Security](<https://devfeed.tech/topics/security.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [amazon-web-services](<https://devfeed.tech/tags/amazon-web-services.md>), [backups](<https://devfeed.tech/tags/backups.md>), [database](<https://devfeed.tech/tags/database.md>), [email](<https://devfeed.tech/tags/email.md>), [git](<https://devfeed.tech/tags/git.md>), [github](<https://devfeed.tech/tags/github.md>), [gradle](<https://devfeed.tech/tags/gradle.md>), [incident](<https://devfeed.tech/tags/incident.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

Gradle reports that an AWS key exposing access to development database backups was committed to Git and remained exposed for two hours. The incident potentially affected personal information belonging to Gradle Plugin Portal and Discourse users, including email addresses, usernames, display names, and in some cases hashed and salted passwords. Gradle states that unauthorized access is unlikely and that no account activity related to the potentially affected passwords was detected.

## Source excerpt

On 16th August 2022, Gradle Plugin Portal and the Gradle Discourse forums were impacted by a security incident that could have led to exposure of the personal data of some Gradle community members. No other services, hosted on gradle.org, gradle.com, or elsewhere were impacted. What happened? An Amazon Web Services key granting access to database backups that contained personal information for a subset of the Gradle Plugin Portal and Discourse forum users was exposed in a Git commit. This key was exposed for two hours before being revoked. We believe it is unlikely that the exposure led to an unauthorized access of data, but we are taking actions and notifying impacted individuals out of caution and transparency. What data was exposed? We have inspected the database backups to determine what data could have been accessed. The backups were from the development environment that contained data for the Gradle Plugin Portal and Discourse users. We are emailing affected users to notify them specifically of this incident. If you do not receive an email from us about this incident, you are not affected by it. The personal data that could have been impacted by the incident likely varies depending on the user but could include information such as email address, display names, and for some individuals, hashed and salted passwords. We have confirmed that no activity has occurred with respect to any account related to any of the hashed and salted passwords potentially impacted by the incident. The following data could have been exposed: 7133 display names, usernames and potential GitHub usernames and email addresses for all users that were present in the development database of the Gradle Plugin Portal Display name and username are already public on the Plugin Portal or Discourse. So is the association with the GitHub username when using GitHub as the identity provider. However, emails are not public on the Plugin Portal or Discourse. If the database was downloaded by a third pa