api keys leaked

Disclosed: 2022-11-10 14:40:41 By saibalaji143_ To reddit
Medium
Vulnerability Details
## Summary: [Disclosure of valid private keys may lead to unauthorized access to any systems that use them for authentication. Verify whether any keys disclosed are actually valid, and whether their disclosure within the application is appropriate] ## Impact: [Disclosure of valid private keys may lead to unauthorized access to any systems that use them for authentication. Verify whether any keys disclosed are actually valid, and whether their disclosure within the application is appropriate] ## Steps To Reproduce: [add details for how we can reproduce the issue] 1. open the url redditinc.com 2. copy the "redditinc" from url 3. using gitdork ("redditinc" apikey) 4.open github search the gitdork 5.check the results ## Supporting Material/References: [list any additional material (e.g. screenshots, logs, etc.)] * [attachment / reference] ## Impact Disclosure of valid private keys may lead to unauthorized access to any systems that use them for authentication. Verify whether any keys disclosed are actually valid, and whether their disclosure within the application is appropriate
Actions
View on HackerOne
Report Stats
  • Report ID: 1762927
  • State: Closed
  • Substate: informative
  • Upvotes: 11
Share this report