logo

Database

Freshdesk Api Key

Description

The source code repository contains sensitive information: Freshdesk API Key

Weakness:

009 - Sensitive information in source code

Category: Information Collection

Detection Strategy

    • Matches Freshdesk API Key patterns in source code and configuration files

Vulnerable code example

FRESHDESK_API_KEY=Xq7vR2mK9pLwTz4nB8cQ
FRESHDESK_DOMAIN=acme.freshdesk.com
FRESHDESK_API_KEY=Xq7vR2mK9pLwTz4nB8cQ
curl -v -u Xq7vR2mK9pLwTz4nB8cQ:X -H "Content-Type: application/json" https://acme.freshdesk.com/api/v2/tickets
requests.get("https://acme.freshdesk.com/api/v2/agents/me", auth=("Xq7vR2mK9pLwTz4nB8cQ", "X"))
freshdesk:
  domain: acme-support.freshdesk.com
  api_key: 'Hk3dW9fP2xNaRm6tJ1gZ'...