Loading HuntDB...

api keys leaked

Medium
R
Reddit
Submitted None
Reported by saibalaji143_

Vulnerability Details

Technical details and impact analysis

Improper Access Control - Generic
## Summary: [Disclosure of valid private keys may lead to unauthorized access to any systems that use them for authentication. Verify whether any keys disclosed are actually valid, and whether their disclosure within the application is appropriate] ## Impact: [Disclosure of valid private keys may lead to unauthorized access to any systems that use them for authentication. Verify whether any keys disclosed are actually valid, and whether their disclosure within the application is appropriate] ## Steps To Reproduce: [add details for how we can reproduce the issue] 1. open the url redditinc.com 2. copy the "redditinc" from url 3. using gitdork ("redditinc" apikey) 4.open github search the gitdork 5.check the results ## Supporting Material/References: [list any additional material (e.g. screenshots, logs, etc.)] * [attachment / reference] ## Impact Disclosure of valid private keys may lead to unauthorized access to any systems that use them for authentication. Verify whether any keys disclosed are actually valid, and whether their disclosure within the application is appropriate

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Improper Access Control - Generic