Azure Devops Personal Access Token

Description

The source code repository contains sensitive information: Azure DevOps Personal Access Token

Weakness:

009 - Sensitive information in source code

Category: Information Collection

Detection Strategy

    Matches Azure DevOps Personal Access Token patterns in source code and configuration files

Vulnerable code example

AZURE_DEVOPS_PAT=abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnop
azure_pat: :xK9mP2nQr7sT4vW1yB5fH8jL3cZ6bN0dV2gE7hU4aF1iM9oY5Xp2Rk3BqW8nJs6LtFp4Vy0Rk7MaAZDOZq3B
AZURE_DEVOPS_PAT=xK9mP2nQr7sT4vW1yB5fH8jL3cZ6bN0dV2gE7hU4aF1iM9oY5Xp2Rk3BqW8nJs6LtFp4Vy0Rk7MaAZDOZq3B