Loading HuntDB...

Datadog api keys exposed can be used to do all the read and write access to the instance

Critical
M
Mars
Submitted None

Team Summary

Official summary from Mars

The researcher identified DatadogHQ API keys and application keys embedded in a JavaScript (JS) file on the site █████. These keys could potentially provide unauthorized access to DatadogHQ services. The researcher responsibly reported the issue, providing a proof-of-concept (PoC) to demonstrate the vulnerability without exploiting it further.

Reported by harshdranjan

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure