logo

284 Non-encrypted confidential information - Base 64


Description

Base64 credentials are stored in the source code.


Impact

Obtain service credentials.


Recommendation

- Change the login credentials that were compromised. - Purge git history of affected sensitive data. - Upload sensitive data from secure sources such as: key vault services, configuration files that are properly encrypted.


Threat

Attacker with access to source code from the Internet.


Expected Remediation Time

60 minutes.


Score 4.0

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

  • Attack vector: N
  • Attack complexity: L
  • Attack Requirements: N
  • Privileges required: L
  • User interaction: N
  • Confidentiality (VC): L
  • Integrity (VI): N
  • Availability (VA): N
  • Confidentiality (SC): N
  • Integrity (SI): N
  • Availability (SA): N

Threat 4.0

  • Exploit maturity: X

Requirements


Fixes


Last updated

2024/02/18