InfoTrackGlobal / juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
https://owasp-juice.shop
MIT License
0 stars 0 forks source link

Secrets Dashboard #3

Open nullify-infotrack[bot] opened 3 months ago

nullify-infotrack[bot] commented 3 months ago

157 potential secrets found in repository

Secret Type Count
Generic API Key 88
HashiCorp Terraform password field 26
JSON Web Token 41
Private Key 2

ID: 01HTEBKQB7376Y0SJWQP8RP583 HashiCorp Terraform password field First Commit Time: 2014-09-19T14:53:16Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/server.js#L46 # ID: 01HTEBKQB7376Y0SJWQRAWN7F5 HashiCorp Terraform password field First Commit Time: 2014-09-19T14:53:16Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/server.js#L54 # ID: 01HTEBKQB7376Y0SJWQM3TD7RY Generic API Key First Commit Time: 2014-09-19T15:39:04Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/.travis.yml#L8 # ID: 01HTEBKQB7376Y0SJWQDH208NA HashiCorp Terraform password field First Commit Time: 2014-09-19T16:07:39Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/server.js#L51 # ID: 01HTEBKQB7376Y0SJWQH9YQKH7 HashiCorp Terraform password field First Commit Time: 2014-09-19T16:07:39Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/server.js#L59 # ID: 01HTEBKQB7376Y0SJWQB2W1GRT Generic API Key First Commit Time: 2014-09-30T11:19:49Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/server.js#L24 # ID: 01HTEBKQB7376Y0SJWQ73NGARM Generic API Key First Commit Time: 2016-10-24T21:52:59Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/data/datacreator.js#L317 # ID: 01HTEBKQB7376Y0SJWQA12VWBD Generic API Key First Commit Time: 2016-10-24T21:52:59Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/routes/login.js#L13 # ID: 01HTEBKQB7376Y0SJWQ43VXVMY Generic API Key First Commit Time: 2016-10-25T00:14:02Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/server/userApiSpec.js#L190 # ID: 01HTEBKQB7376Y0SJWQ0VXBECX Generic API Key First Commit Time: 2017-06-16T14:48:33Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/data/datacreator.js#L510 # ID: 01HTEBKQB7376Y0SJWPTC1S9B7 Generic API Key First Commit Time: 2017-07-28T13:45:52Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/basketApiSpec.js#L94 # ID: 01HTEBKQB7376Y0SJWPS9217WR Generic API Key First Commit Time: 2017-07-28T13:45:52Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/feedbackApiSpec.js#L112 # ID: 01HTEBKQB7376Y0SJWPQQX7169 Generic API Key First Commit Time: 2017-07-28T13:45:52Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/feedbackApiSpec.js#L85 # ID: 01HTEBKQB7376Y0SJWPTEMY491 Generic API Key First Commit Time: 2017-07-28T13:45:52Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/userApiSpec.js#L122 # ID: 01HTEBKQB7376Y0SJWPXA1RPEV Generic API Key First Commit Time: 2017-07-28T13:45:52Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/userApiSpec.js#L249 # ID: 01HTEBKQB7376Y0SJWPXKS6516 Generic API Key First Commit Time: 2017-07-28T13:45:52Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/userApiSpec.js#L414 # ID: 01HTEBKQB7376Y0SJWPHDW0P7E Generic API Key First Commit Time: 2017-08-06T09:22:47Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/basketApiSpec.js#L94 # ID: 01HTEBKQB7376Y0SJWPK0ND7MJ Generic API Key First Commit Time: 2017-08-06T09:22:47Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/feedbackApiSpec.js#L112 # ID: 01HTEBKQB7376Y0SJWPHVRW0KS Generic API Key First Commit Time: 2017-08-06T09:22:47Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/feedbackApiSpec.js#L85 # ID: 01HTEBKQB7376Y0SJWPKRGJY13 Generic API Key First Commit Time: 2017-08-06T09:22:47Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/userApiSpec.js#L122 # ID: 01HTEBKQB7376Y0SJWPNBYY12B Generic API Key First Commit Time: 2017-08-06T09:22:47Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/userApiSpec.js#L249 # ID: 01HTEBKQB7376Y0SJWPQ4GK246 Generic API Key First Commit Time: 2017-08-06T09:22:47Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/userApiSpec.js#L414 # ID: 01HTEBKQB7376Y0SJWPEDKRGKE Private Key First Commit Time: 2017-10-10T20:22:59Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/lib/insecurity.js#L12 # ID: 01HTEBKQB7376Y0SJWPBHTP9YY Private Key First Commit Time: 2017-10-10T20:55:52Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/lib/insecurity.js#L10 # ID: 01HTEBKQB7376Y0SJWP6HDZ4Q9 JSON Web Token First Commit Time: 2017-10-22T03:03:00Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/server/verifySpec.js#L227 # ID: 01HTEBKQB7376Y0SJWP9ATYR0C JSON Web Token First Commit Time: 2017-10-22T03:03:00Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/server/verifySpec.js#L248 # ID: 01HTEBKQB7376Y0SJWP53R3E45 JSON Web Token First Commit Time: 2017-10-24T23:06:04Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/e2e/forgedJwtSpec.js#L13 # ID: 01HTEBKQB7376Y0SJWP2WK9VCM JSON Web Token First Commit Time: 2017-10-24T23:06:04Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/e2e/forgedJwtSpec.js#L4 # ID: 01HTEBKQB7376Y0SJWNZK5V266 JSON Web Token First Commit Time: 2017-10-25T22:55:13Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/server/verifySpec.js#L239 # ID: 01HTEBKQB7376Y0SJWP08PX0J6 JSON Web Token First Commit Time: 2017-10-25T22:55:13Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/server/verifySpec.js#L272 # ID: 01HTEBKQB7376Y0SJWNY86SFFN Generic API Key First Commit Time: 2017-12-02T00:00:18Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/loginApiSpec.js#L94 # ID: 01HTEBKQB7376Y0SJWNZCS03BN Generic API Key First Commit Time: 2017-12-02T00:00:18Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/passwordApiSpec.js#L63 # ID: 01HTEBKQB7376Y0SJWNPW4TXJX JSON Web Token First Commit Time: 2018-01-24T14:09:35Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/server/verifySpec.js#L225 # ID: 01HTEBKQB7376Y0SJWNQXW1MK8 JSON Web Token First Commit Time: 2018-01-24T14:09:35Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/server/verifySpec.js#L237 # ID: 01HTEBKQB7376Y0SJWNT8CVRG0 JSON Web Token First Commit Time: 2018-01-24T14:09:35Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/server/verifySpec.js#L258 # ID: 01HTEBKQB7376Y0SJWNXZ8SHE9 JSON Web Token First Commit Time: 2018-01-24T14:09:35Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/server/verifySpec.js#L270 # ID: 01HTEBKQB7376Y0SJWNKS2G50N Generic API Key First Commit Time: 2018-03-04T18:25:41Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/data/data/users.json#L22 # ID: 01HTEBKQB7376Y0SJWNGN9TZ83 Generic API Key First Commit Time: 2018-03-06T15:01:40Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/data/static/users.yml#L15 # ID: 01HTEBKQB7376Y0SJWNEVJ7DCE Generic API Key First Commit Time: 2018-03-14T12:49:34Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/data/static/users.yml#L18 # ID: 01HTEBKQB7376Y0SJWNDFK9JTA HashiCorp Terraform password field First Commit Time: 2018-05-18T13:57:38Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/frontend/src/app/login/login.component.html#L18 # ID: 01HTEBKQB7376Y0SJWN9W9PEAQ Generic API Key First Commit Time: 2018-06-03T18:51:07Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/frontend/src/app/basket/basket.component.html#L80 # ID: 01HTEBKQB7376Y0SJWN7Z44A9S JSON Web Token First Commit Time: 2018-06-30T15:15:32Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/e2e/forgedJwtSpec.js#L14 # ID: 01HTEBKQB7376Y0SJWN9ESK97S JSON Web Token First Commit Time: 2018-06-30T15:15:32Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/e2e/forgedJwtSpec.js#L15 # ID: 01HTEBKQB7376Y0SJWN6BK363Z JSON Web Token First Commit Time: 2018-06-30T15:15:32Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/e2e/forgedJwtSpec.js#L4 # ID: 01HTEBKQB7376Y0SJWN6KB4SM0 JSON Web Token First Commit Time: 2018-06-30T15:15:32Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/e2e/forgedJwtSpec.js#L5 # ID: 01HTEBKQB7376Y0SJWN4ZCN66A HashiCorp Terraform password field First Commit Time: 2018-09-14T15:53:51Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/frontend/src/app/login/login.component.html#L19 # ID: 01HTEBKQB7376Y0SJWMYD5E27Q Generic API Key First Commit Time: 2018-11-06T09:28:03Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/data/static/users.yml#L18 # ID: 01HTEBKQB7376Y0SJWN1M9BCN6 Generic API Key First Commit Time: 2018-11-06T09:28:03Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/loginApiSpec.js#L125 # ID: 01HTEBKQB7376Y0SJWMG608RBN Generic API Key First Commit Time: 2018-11-07T00:11:37Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/routes/login.js#L41 # ID: 01HTEBKQB7376Y0SJWMDHXNHC4 Generic API Key First Commit Time: 2018-11-07T00:11:37Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/basketApiSpec.js#L81 # ID: 01HTEBKQB7376Y0SJWMQ29CH87 Generic API Key First Commit Time: 2018-11-07T00:11:37Z https://github.com/InfoTrackGlobal/juice-shop/blob/6276c9e088840d5c95390c462fbd5b2fc33c6c51/test/api/feedbackApiSpec.js#L110 #

ℹ️ Note: 157 secrets were detected. This dashboard only prioritises and showcases the top 50 secrets.

Reply with /nullify to interact with me like another developer

If you'd like me to allowlist a secret, you can do so by commenting on this issue with an allowlist reason and I'll open a pull request to update the Nullify config file

For example, /nullify allowlist <secret-value> as it has been rotated

WillCohenInfotrack commented 3 months ago

/nullify allowlist "-----BEGIN RSA PRIVATE KEY-----\r\nMIICXAIBAAKBgQDNwqLEe9wgTXCbC7+RPdDbBbeqjdbs4kOPOIGzqLpXvJXlxxW8iMz0EaM4BKUqYsIa+ndv3NAn2RxCd5ubVdJJcX43zO6Ko0TFEZx/65gY3BE0O6syCEmUP4qbSd6exou/F+WTISzbQ5FBVPVmhnYhG/kpwt/cIxK5iUn5hm+4tQIDAQABAoGBAI+8xiPoOrA+KMnG/T4jJsG6TsHQcDHvJi7o1IKC/hnIXha0atTX5AUkRRce95qSfvKFweXdJXSQ0JMGJyfuXgU6dI0TcseFRfewXAa/ssxAC+iUVR6KUMh1PE2wXLitfeI6JLvVtrBYswm2I7CtY0q8n5AGimHWVXJPLfGV7m0BAkEA+fqFt2LXbLtyg6wZyxMA/cnmt5Nt3U2dAu77MzFJvibANUNHE4HPLZxjGNXN+a6m0K6TD4kDdh5HfUYLWWRBYQJBANK3carmulBwqzcDBjsJ0YrIONBpCAsXxk8idXb8jL9aNIg15Wumm2enqqObahDHB5jnGOLmbasizvSVqypfM9UCQCQl8xIqy+YgURXzXCN+kwUgHinrutZms87Jyi+D8Br8NY0+Nlf+zHvXAomD2W5CsEK7C+8SLBr3k/TsnRWHJuECQHFE9RA2OP8WoaLPuGCyFXaxzICThSRZYluVnWkZtxsBhW2W8z1b8PvWUE7kMy7TnkzeJS2LSnaNHoyxi7IaPQUCQCwWU4U+v4lD7uYBw00Ga/xt+7+UqFPlPVdz1yyr4q24Zxaw0LgmuEvgU5dycq8N7JxjTubX0MIRR+G9fmDBBl8=\r\n-----END RSA PRIVATE KEY-----" as it has been rotated

WillCohenInfotrack commented 3 months ago

/nullify allowlist 'bW9jLmxpYW1lbGdvb2dAaGNpbmltbWlrLm5yZW9qYg==' as it has been rotated