IntersectMBO / IntersectMBO/govtool

🐛 [Bounty] - Sensitive Data Leak through github

Open
#4,144 3 comments 0 reactions 1 assignee Assigned to @kusssal View on GitHub
🐛 Bug 👀 Triaged 📜 Proposal Pillar
Dominant language
HTML
Stars
21
Forks
29
Avg merge
2d 22h
Merged PRs (30d)
7

Description

### Context

**Received via the security mailbox. I’m catching up on the backlog and couldn’t find any logs for this one, so I’m adding it here for tracking purposes. Please feel free to close it if it has already been processed.**

Hi Team,

I found some sensitive data from github

Image
Github link:-https://github.com/IntersectMBO/govtool/blob/7bebf5186eab1527acc202978401c3607b306e5b/.github/workflows/frontend_sonar_scan.yml#L44

Image

Github link: https://github.com/IntersectMBO/govtool/blob/6ba37d8c62c37979d88faae1d98082380721e21c/.github/workflows/frontend_sonar_scan.yml#L22

### Steps to reproduce

**Validation**
curl -u "ec4183646e59dd70c8077acfabe52062ccbea7a9:" "https://sonarcloud.io/api/system/status"

Image

### Actual behavior

### Impact
- Data Breach: Potential access to user data
- Financial Loss: Unauthorized transactions
- Service Disruption: Resource manipulation
- Reputation Damage: Loss of customer trust

### Expected behavior

### Recommendations
**1. Immediate Actions:**
- Rotate all exposed API keys immediately
- Remove sensitive files from Git history using BFG Repo-Cleaner or git filter-branch
- Add the affected files to .gitignore

**2. Preventive Measures:**
- Implement pre-commit hooks with secret detection
- Use environment variables for configuration
- Regular security scanning of repositories
- Developer training on secure coding practices

**3. Tooling:**
- Implement git-secrets or similar tools
- Use CI/CD security scanning (GitGuardian, TruffleHog)
- Regular external penetration testing

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.