Loading HuntDB...

Leaking sensitive information lead to compromise employer API keys

High
Y
Yelp
Submitted None

Team Summary

Official summary from Yelp

The configuration file of an internal IRC bot (which included credentials to internal services and some external services used by Yelp developers) was inadvertently included by an employee in a personal public GitHub repository. The repository was taken down and the affected credentials rotated.

Reported by xsam

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Storage of Sensitive Information