cyates-checkmarx / terragoat

TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
https://www.bridgecrew.io/
Apache License 2.0
0 stars 0 forks source link

CX TruffleHog_HighEntropy_Strings @ packages/node/base/dep.txt [master] #15

Open cyates-checkmarx opened 7 months ago

cyates-checkmarx commented 7 months ago

TruffleHog_HighEntropy_Strings issue exists @ packages/node/base/dep.txt in branch master

*The application uses the hard-coded password 0-486b6e2b6388e2bebf19e6daf0b4b997df62693c for authentication purposes, either using it to verify users' identities, or to access another remote system. This password at line 1252 of packages\node\base\dep.txt appears in the code, implying it is accessible to anyone with source code access, and cannot be changed without rebuilding the application.Similarity ID: 242501632

The application uses the hard-coded password e4a13cfd135ec766dc9148ba4fe4d3ac76d94137 for authentication purposes, either using it to verify users' identities, or to access another remote system. This password at line 1252 of packages\node\base\dep.txt appears in the code, implying it is accessible to anyone with source code access, and cannot be changed without rebuilding the application.Similarity ID: -205368416*

Severity: Low

CWE:798

Checkmarx

Training Recommended Fix

Lines: 1252


Code (Line #1252):

??? @angular/dev-infra-private@0.0.0-486b6e2b6388e2bebf19e6daf0b4b997df62693c (git+https://github.com/angular/dev-infra-private-builds.git#e4a13cfd135ec766dc9148ba4fe4d3ac76d94137)

cyates-checkmarx commented 7 months ago

Issue still exists.

cyates-checkmarx commented 7 months ago

Issue still exists.

cyates-checkmarx commented 7 months ago

Issue still exists.

cyates-checkmarx commented 7 months ago

Issue still exists.

cyates-checkmarx commented 7 months ago

Issue still exists.

cyates-checkmarx commented 7 months ago

Issue still exists.

cyates-checkmarx commented 7 months ago

Issue still exists.

cyates-checkmarx commented 7 months ago

Issue still exists.