Loading HuntDB...

SAUCE Access_key and User_name leaked in Travis CI build logs

Medium
A
Algolia
Submitted None
Reported by an0n-j

Vulnerability Details

Technical details and impact analysis

Information Disclosure
hello algolia team, I founded the SAUCE Access_Key and User_name was leaked in Travis CI build logs of instantsearch.js product [#Line-249-&-250](https://travis-ci.org/algolia/instantsearch.js/builds/225176027#L249). This can be used to perform every API calls of sauce-lab.(e.g Creating a Sub account. I created a test account for testing. sorry for this ;) ). You should revoke the access_key and secure the key in Travis Cl build logs.

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure