logo

Database

Jumpcloud Api Key

Description

The source code repository contains sensitive information: JumpCloud API Key

Weakness:

009 - Sensitive information in source code

Category: Information Collection

Detection Strategy

    • Matches JumpCloud API Key patterns in source code and configuration files

Vulnerable code example

JUMPCLOUD_API_KEY=jca_ThrAcLlpnPYXABrlaWtYBmkt4tP6aNIeeU0w
$env:JCApiKey = 'jca_tRuXJFyKPoT4ckafc0B69xGTFz01PgJXsOj7'
curl -H "x-api-key: jca_vYHwz5RBbGuMVL59KJ0DKd2Qyrewr2LMWmuZ" https://console.jumpcloud.com/api/systemusers