Security Incident Review: API Endpoint Exposure on accounts.eclipse.org
In late March 2025, a security researcher in our community reported a security concern about a publicly accessible API endpoint containing user information on accounts.eclipse.org. After reviewing the issue, we determined this API endpoint was unnecessary and have since disabled it. We looked through our access logs for the past...