Home / vulnerabilitiesPDF  

Bio Basespace SDK 0.1.7 API Key Exposure

Posted on 16 December 2013
Source : packetstormsecurity.org Link

 

The Bio Basespace SDK 0.1.7 Ruby Gem API client code passes the API_KEY to a curl command. This exposes the api key to the shell and process table. Another user on the system could snag the api key by just monitoring the process table.

 

TOP