Confluence Data Center Personal Access Token
Description
The source code repository contains sensitive information: Confluence Data Center Personal Access Token
Detection Strategy
• Matches Confluence Data Center Personal Access Token patterns in source code and configuration files
Vulnerable code example
CONFLUENCE_PAT=NDgzOTIwMTc1NjM0OpxOG3o/XSBo4cOlt9nwJGis4TV5
curl -H "Authorization: Bearer NDgzOTIwMTc1NjM0OpxOG3o/XSBo4cOlt9nwJGis4TV5" https://confluence.example.com/rest/api/user/current
confluence = Confluence(url="https://wiki.example.com", token="MDcxMjY1NDM4MjkwOh8uPUxbanmIB5altMPS4fAPHi08")
confluence:
url: https://confluence.internal
personal_access_token: 'MDcxMjY1NDM4MjkwOh8uPUxbanmIB5altMPS4fAPHi08'Free trial
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.