Loading HuntDB...

sensitive data-creds for database - private key

Medium
M
Mars
Submitted None

Team Summary

Official summary from Mars

A set of sensitive database credentials has been discovered in a publicly accessible GitHub repository. The exposed credentials include a username and password for a database named "█████████" along with a private key. The credentials are stored in plaintext within a configuration file, making them directly accessible to anyone who can view the repository. This exposure represents a significant security risk as it violates the principle of secure credential management.

Reported by mo_salah12

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Missing Encryption of Sensitive Data