api keys leaked
Medium
R
Reddit
Submitted None
Actions:
Reported by
saibalaji143_
Vulnerability Details
Technical details and impact analysis
## Summary:
[Disclosure of valid private keys may lead to unauthorized access to any systems that use them for authentication. Verify whether any keys disclosed are actually valid, and whether their disclosure within the application is appropriate]
## Impact:
[Disclosure of valid private keys may lead to unauthorized access to any systems that use them for authentication. Verify whether any keys disclosed are actually valid, and whether their disclosure within the application is appropriate]
## Steps To Reproduce:
[add details for how we can reproduce the issue]
1. open the url redditinc.com
2. copy the "redditinc" from url
3. using gitdork ("redditinc" apikey)
4.open github search the gitdork
5.check the results
## Supporting Material/References:
[list any additional material (e.g. screenshots, logs, etc.)]
* [attachment / reference]
## Impact
Disclosure of valid private keys may lead to unauthorized access to any systems that use them for authentication. Verify whether any keys disclosed are actually valid, and whether their disclosure within the application is appropriate
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Improper Access Control - Generic