284 – Non-encrypted confidential information - Base 64
Description
Base64 credentials are stored in the source code.
Impact
Obtain service credentials.
Recommendation
- Change the login credentials that were compromised. - Purge git history of affected sensitive data. - Upload sensitive data from secure sources such as: key vault services, configuration files that are properly encrypted.
Threat
Attacker with access to source code from the Internet.
Expected Remediation Time
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: N
- Attack complexity: L
- Attack Requirements: N
- Privileges required: L
- User interaction: N
- Confidentiality (VC): L
- Integrity (VI): N
- Availability (VA): N
- Confidentiality (SC): N
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
- Exploit maturity: X