sensitive data-creds for database - private key
Medium
M
Mars
Submitted None
Team Summary
Official summary from Mars
A set of sensitive database credentials has been discovered in a publicly accessible GitHub repository. The exposed credentials include a username and password for a database named "█████████" along with a private key. The credentials are stored in plaintext within a configuration file, making them directly accessible to anyone who can view the repository. This exposure represents a significant security risk as it violates the principle of secure credential management.
Actions:
Reported by
mo_salah12
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Missing Encryption of Sensitive Data