PT-2023-25708 · Stripe · Stripe Api

Vamsii777

·

Publicado

2023-07-03

·

Atualizado

2023-07-10

·

CVE-2023-36817

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions tktchurch/website version 0.1.0
Description The codebase for The King's Temple Church website contains a Stripe API key that was unintentionally committed and exposed. This sensitive information could be used by unauthorized parties to carry out transactions on behalf of the organization, leading to financial losses, and access sensitive customer information, resulting in privacy violations and potential legal implications. The affected component is the codebase, specifically the file(s) where the Stripe API key is embedded.
Recommendations For version 0.1.0, the maintainers plan to revoke the leaked Stripe API key immediately, generate a new one, and ensure it is not committed to the codebase. As a temporary workaround, consider restricting access to the affected file(s) where the Stripe API key is embedded until the issue is resolved.

Exploit

Correção

Information Disclosure

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-36817
GHSA-X3M6-5HMF-5X3W

Produtos afetados

Stripe Api