SAUCE Access_key and User_name leaked in Travis CI build logs
Medium
A
Algolia
Submitted None
Actions:
Reported by
an0n-j
Vulnerability Details
Technical details and impact analysis
hello algolia team,
I founded the SAUCE Access_Key and User_name was leaked in Travis CI build logs of instantsearch.js product [#Line-249-&-250](https://travis-ci.org/algolia/instantsearch.js/builds/225176027#L249).
This can be used to perform every API calls of sauce-lab.(e.g Creating a Sub account. I created a test account for testing. sorry for this ;) ).
You should revoke the access_key and secure the key in Travis Cl build logs.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure