Datadog api keys exposed can be used to do all the read and write access to the instance
Critical
M
Mars
Submitted None
Team Summary
Official summary from Mars
The researcher identified DatadogHQ API keys and application keys embedded in a JavaScript (JS) file on the site █████. These keys could potentially provide unauthorized access to DatadogHQ services. The researcher responsibly reported the issue, providing a proof-of-concept (PoC) to demonstrate the vulnerability without exploiting it further.
Actions:
Reported by
harshdranjan
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure