Secret_key in GitHub
None
W
Weblate
Submitted None
Actions:
Reported by
fr0gz0x
Vulnerability Details
Technical details and impact analysis
hello
I have found secret_key in GitHub is public and noticed something this key have comment # Make this unique, and don't share it with anybody. and it's public in GitHub also I noticed this file has coding to do the payment.db I think information like this must be private
SECRET_KEY = "qov6(*cp%)b*ot+8c%#4@4or(t@_$y5#d8k9u1^+pknz%lms0x"
Link : https://github.com/WeblateOrg/website/blob/bc65d95a80d90ed95a8e59d0fa5dc14d7c060b3a/weblate_web/settings.py
## Impact
i don't know what attacker can do but i know this info must be private
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Information Disclosure