Asana Personal Access Token
Description
The source code repository contains sensitive information: Asana Personal Access Token
Detection Strategy
• Matches Asana Personal Access Token patterns in source code and configuration files
Vulnerable code example
ASANA_PAT=1/1204938572610934:3f9a1c7e5b2d4086a1e3c5b7d9f02468
export ASANA_ACCESS_TOKEN="2/1204938572610934/1207719384650213:9e2b4d6f8a0c1e3f5a7b9c1d3e5f7a9b"
asana_personal_access_token: '1/1204938572610934:3f9a1c7e5b2d4086a1e3c5b7d9f02468'
client = asana.Client.access_token("2/1204938572610934/1207719384650213:9e2b4d6f8a0c1e3f5a7b9c1d3e5f7a9b")
curl https://app.asana.com/api/1.0/users/me -H "Authorization: Bearer 1/1204938572610934:3f9a1c7e5b2d4086a1e3c5b7d9f02468"
ASANA_TOKEN=0/7c3e9a1f5b2d8046e1a3c5b7d9f0Free trial
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.