326 – Sensitive information in source code - Dependencies
Description
By reversing the application dependencies, it is found that the private key has been stored in the same dependency and not in a protected environment.
Impact
Obtain the private key used to decrypt the information.
Recommendation
Securely configure the vulnerable service so that it can only be accessed by authorized users.
Threat
Internal attacker with access to the artifactory.
Expected Remediation Time
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: A
- Attack complexity: L
- Attack Requirements: N
- Privileges required: L
- User interaction: N
- Confidentiality (VC): H
- Integrity (VI): N
- Availability (VA): N
- Confidentiality (SC): N
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
- Exploit maturity: X