Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Generic Key was found in the code of a public repository #2

Open
ox-barazouri opened this issue Aug 1, 2024 · 0 comments
Open

Generic Key was found in the code of a public repository #2

ox-barazouri opened this issue Aug 1, 2024 · 0 comments

Comments

@ox-barazouri
Copy link

ox-barazouri commented Aug 1, 2024

  • Category: Secret/PII Scan
  • Policy Name: Secret in code
  • Application Name: oxsecurity/MaskerLogger
  • Fix Link:
  • Click here to see details in OX App:

Issue Description:

A key for a system was discovered. Unfortunately, we were unable to determine the system/app the key was generated from. Manual identification and investigation of the key is required to determine the actual risk.

Recommendations:

Please verify if the Generic Key in the code is in use. Then do the following:

1. If the secret is in use, please revoke it.
2. Moving forward, store secrets in an environment variable or secret manager.
3. Change the code to access secrets using the method chosen above.

WARNING: The found Generic Key will still be visible in the Git History. Ensure it is revoked/disabled.

Aggregations:












File Line Match Commit By Open ticket day Commit Message Type Merged by Reviewers Commit Date Location Parameter Test CVSS Alert Link
maskerlogger/secrets_in_logs_example.py 21 logger.info('"current_key": "AIzaSOHbouG6DDa6DOc*******************"', extra=SKIP_MASK) # noqa Tamar Galer [email protected] add option to set fix masking len

Signed-off-by: Tamar Galer <[email protected]>

2024-07-10 19:26:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant