logo

326 Sensitive information in source code - Dependencies


Description

By reversing the application dependencies, it is found that the private key has been stored in the same dependency and not in a protected environment.


Impact

Obtain the private key used to decrypt the information.


Recommendation

Securely configure the vulnerable service so that it can only be accessed by authorized users.


Threat

Internal attacker with access to the artifactory.


Expected Remediation Time

60 minutes.


Score 4.0

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

  • Attack vector: A
  • Attack complexity: L
  • Attack Requirements: N
  • Privileges required: L
  • User interaction: N
  • Confidentiality (VC): H
  • Integrity (VI): N
  • Availability (VA): N
  • Confidentiality (SC): N
  • Integrity (SI): N
  • Availability (SA): N

Threat 4.0

  • Exploit maturity: X

Requirements


Fixes


Last updated

2024/02/19