exadel-inc / exadel-inc/CompreFace

Security issue: default API keys

Open
#1,217 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
8.3k
Forks
1.2k
PR merge metrics
No merged PRs in 30d

Description

**Describe the bug**

CompreFace has default demo services and default hardcoded API keys
- https://github.com/exadel-inc/CompreFace/issues/1035#issuecomment-1456389576
- https://github.com/exadel-inc/CompreFace/blob/ddf32da8245e2e6688c3ab6f60587fd3e31538c2/java/admin/src/main/resources/db/changelog/db.changelog-0.1.8.yaml#L31

So, it's possible to use some private instances of CompreFace if demo services were not removed just using default API keys.

**To Reproduce**

You can find CompreFace instances in such services like Netlas, Censys, Shodan and so on, just filtering pages with keyword `Compeface`. Netlas is giving 123 known instances: https://app.netlas.io/responses/?q=http.body%3ACompreface&page=1&indices=

**Expected behavior**

Demo services have randomly generated API keys.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.