Property
Languageregex
Severitylow
CWECWE-798: Use of Hard-coded Credentials
OWASPA07:2021 - Identification and Authentication Failures
Confidence LevelLow
Impact LevelMedium
Likelihood LevelLow

Description#

A Kolide API key appears to be hard-coded or exposed in your codebase. Exposing secret credentials in source code can allow unauthorized access to Kolide services.

Impact#

If this API key is leaked, attackers could gain control over your Kolide instance, potentially accessing sensitive data, executing commands, or altering configurations. This may lead to data breaches, unauthorized activity, or loss of control over your infrastructure.