Gcp Service Account Key

Description

The source code repository contains sensitive information: GCP Service Account Key

Weakness:

009 - Sensitive information in source code

Category: Information Collection

Detection Strategy

    Matches GCP Service Account Key patterns in source code and configuration files

Vulnerable code example

{
  "type": "service_account",
  "project_id": "my-project",
  "private_key_id": "1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b",
  "private_key": "-----BEGIN PRIVATE KEY-----\nMIIEvAIBADANBgkqhkiG9w0BAQEFAASCBKYwggSiAgEAAoIBAQC7o4qne60TB3wo\npGMKjOaHBSELep5JY6e5zDKTDQMmSHQRDWCQJxgcjKMFmGJ3Ri2oexAZOKQYpx\nHKmOt9vFKTm3bMWByBRgx1tIKERNSfCk7oMLhAqL4VpUmT2Yn8mZtJa4Ri5Dkp\nFQwZ8XaLjN6cVfHme9PKtUsTq7Yb0RGz2vNsKOlBwMh5XdEiAuW3cTqPl6Rvs0\nY3hGkZpJNwBmRoE8VzQtKH9UlLcX4ybMF2GDsTaWf0iPeNvQkJ7LAuMCr8nBXT\nOp6VwQH+RKEfD2sJmN5cAyPgIbXu0TZhWl9qKvFnE7R3MdsYoCtU1V4gXiBj6O\nAgMBAAECggEABqbDhwHmHNPpFxnCmS7v1fFBQr5aCdPo9FfXYe2Y8T3C8Ktzj3\nQ+ZhvPyR2mCsLiN4oTpAoGv0kBj7uX9YmPCl3XYaXnTyW8dLsR5Qx1rHoFVb\n-----END PRIVATE KEY-----\n",
  "client_email": "[email protected]",
  "client_id": "123456789012345678901",
  "auth_uri": "https://accounts.google.com/o/oauth2/auth",...