Tuesday, 02 January 2024 12:17 GMT

Leaked Github App Keys Retain Live Access Arabian Post


(MENAFN- The Arabian Post) clearfix">Hundreds of GitHub App private keys exposed in public code remain valid, allowing authentication to GitHub and, in some cases, access to private repositories and organisation-level controls, security researchers have found.

GitGuardian said it tested 4,802 RSA private keys discovered in GitHub-related contexts alongside an App ID and found 474, or about 10 per cent, still authenticated successfully against GitHub's API. Those keys represented 440 distinct GitHub Apps, underscoring the persistence of credentials that remain usable until manually revoked.

The findings, published on September 22, followed an analysis of more than 500,000 exposed RSA private keys collected in GitGuardian's dataset of publicly leaked secrets. Researchers narrowed the pool to keys associated with GitHub Apps, then signed JSON Web Tokens and queried GitHub's /app API endpoint to establish whether each credential was still valid.

MENAFN24092026000152002308ID1111708512



The Arabian Post

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story