During a scan for data leaks conducted by RedHunt Labs on GitHub repositories, a publication was found in a public repository of an API token that allows unrestricted access to the internal repositories of Mercedes-Benz, hosted on an internal server based on GitHub Enterprise Server. It is believed that the token was accidentally published by one of the employees of Mercedes-Benz among the code hosted in a public repository on GitHub.
The token has been in the repository since September 29, 2023, and was identified on January 11, 2024. After informing the company about the incident on January 24, the token was revoked. According to representatives of Mercedes-Benz, the disclosed token allowed access not to the entire source code hosted on server, but only to certain internal repositories of the company. Additionally, in a message from the researchers who found the token, it was stated that internal repositories that could be accessed using the found token contained confidential technical documentation and information that constitutes commercial secrets, as well as sensitive data such as credentials for database connections, access keys to cloud services, API access keys, and service connection passwords.
It is also worth noting that Escape conducted a scan of one million domains for the presence of keys and API tokens exposed in public. During the scan, which analyzed 189.5 million URLs, 18,458 embedded keys and tokens were identified, of which 41% are critically important, meaning their loss poses significant financial risks. For example, researchers estimate that the amount of funds accessible through tokens left on pages for calling the Stripe API is about 20 million dollars.
Among the sensitive data identified on the pages, access tokens for GitHub (51.5%), GitLab, Stripe (0.9%), OpenAI (1.4%), AWS, Twitch (0.7%), Coinbase, X/Twitter (2.7%), Slack (9.5%), and Discord (1.2%), as well as private RSA keys (26.3%) were mentioned. 35% of the identified keys and tokens were present in JavaScript files. In 2.1% of cases, sensitive data was found in files generated from compiling JavaScript code into a single file.

Source: opennet.ru
