Property
Languageregex
Severitymedium
CWECWE-798: Use of Hard-coded Credentials
OWASPA07:2021 - Identification and Authentication Failures
Confidence LevelLow
Impact LevelHigh
Likelihood LevelLow

Description#

AWS Access Key IDs are hardcoded directly into the codebase. Storing sensitive credentials like these in source code makes them easy to leak if the code is shared or published.

Impact#

If exposed, attackers could use these credentials to access and control your AWS resources, potentially leading to data breaches, unauthorized infrastructure changes, or significant financial loss for your organization.