Private RSA key and Server key exposed on the GitHub repository

Disclosed: 2020-10-22 18:07:16 By njaysec To kubernetes
Medium
Vulnerability Details
Report Submission Form ## Summary: I was searching for sensitive data in Kubernetes repository where I found these private keys. These are private RSA key and private server key, which could be used for unauthorized access. ## Steps To Reproduce: VISIT THESE LINKS Repository : kubernetes / kubernetes https://github.com/kubernetes/kubernetes/blob/ce3ddcd5f691b5777e7b2f4d89cac1da316970b4/staging/src/k8s.io/legacy-cloud-providers/vsphere/vclib/fixtures/ca.key https://github.com/kubernetes/kubernetes/blob/ce3ddcd5f691b5777e7b2f4d89cac1da316970b4/staging/src/k8s.io/legacy-cloud-providers/vsphere/vclib/fixtures/server.key ## Supporting Material/References: https://hackerone.com/reports/50170 https://hackerone.com/reports/638401 ## Impact 1).Private key leakage 2). All of the servers using this key will be compromised
Actions
View on HackerOne
Report Stats
  • Report ID: 876751
  • State: Closed
  • Substate: not-applicable
  • Upvotes: 3
Share this report