Skip to main content

Business information leak - Source Code

Description

Within the source code you get business information, such as:

  • Employee information.
  • Customer information.

Impact

Obtain business information to generate new attack vectors.

Recommendation

According to the classification of the information found, establish the necessary controls so that the information is only accessible to the indicated persons.

Threat

Internal attacker with access to source code.

Expected Remediation Time

⌚ 60 minutes.

Score

Default score using CVSS 3.1. It may change depending on the context of the vulnerability.

Base

  • Attack vector: A
  • Attack complexity: L
  • Privileges required: H
  • User interaction: N
  • Scope: U
  • Confidentiality: L
  • Integrity: N
  • Availability: N

Temporal

  • Exploit code madurity: X
  • Remediation level: X
  • Report confidence: X

Result

  • Vector string: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:X/RL:X/RC:X
  • Score:
    • Base: 2.4
    • Temporal: 2.4
  • Severity:
    • Base: Low
    • Temporal: Low

Code Examples

Compliant code

Sensitive information should be encrypted and stored in a database only accessed with admin privileges

resource "db_storage_rules" "name" {
resource_group_name = db_resource_group.test.name
storage_account_name = db_storage_account.test.name
default_action = "Deny"
}

Non compliant code

There is a file in the source code that stores the employee information

Employees {
ids {
name: "index.html";
phone: "localhost:4446 ssl";
role: "admin";
}
}

Requirements