Overview

During a review of NASA's [REDACTED] web presence, I found that content intended for an authenticated intranet was also reachable through a public route. The exposed material included an employee directory, links to individual profile pages, and internal presentation templates.

Administrative functionality remained protected. The issue did not provide elevated privileges or control over the affected system.

Discovery and validation

The expected intranet location required authentication. An alternative public-facing path, however, served equivalent resources without applying the same access restrictions.

I confirmed the behavior using only the minimum requests needed to establish impact. The hostname, URLs, paths, organizational unit, employee details, and reproduction targets are all replaced with [REDACTED] in this publication.

Redacted view of an affected NASA internal page with organizational identifiers and employee information obscured.
Redacted view of the affected internal page. Organizational identifiers and employee information are obscured.

Impact

Unauthenticated visitors could access limited employee information and follow links to profile pages. Presentation templates intended for internal use were exposed through the same access-control inconsistency.

Because administrative content remained protected and the exposed information was not highly sensitive, the report was assessed as P4 / Low severity. The primary risk was privacy exposure and unintended access to internal resources.

Disclosure and resolution

I responsibly reported the issue to NASA with supporting evidence and private reproduction details. The report was accepted and the affected access-control behavior was resolved.

All hostnames, URLs, paths, organizational-unit names, employee details, and actionable reproduction information have been replaced with [REDACTED].