IP: 18.119.192.100

Your ISP: Analyzing ...

Your location: Analyzing ...

Analyzing ...

We value your privacy

We strive to offer our visitors a safe and customized browsing experience using cookies. By accepting our Cookie Policy, your browsing experience on our website will enhance.

  • english
  • czech
  • portuguese
  • italian
  • spanish
  • french
  • german
  • dutch
  • polish
  • russian
  • ukranian
  • اَلْعَرَبِيَّةُ

A mishandled GitHub token exposed Mercedes-Benz source code

Featured in:

Published at: 2024-02-02 08:03

Mercedes Token Exposed

Ai Generated

A Mishandled GitHub Token Exposes Mercedes-Benz Source Code

Mercedes-Benz, renowned for its history of innovation, luxurious designs, and top build quality, faced a critical security incident. A GitHub token, mistakenly exposed in a public repository by a Mercedes employee, granted unrestricted access to the company's internal GitHub Enterprise Server.

The leaked token provided unmonitored access to the entire source code, including sensitive repositories housing intellectual property. Among the compromised information were database connection strings, cloud access keys, blueprints, design documents, SSO passwords, and API keys.

The consequences of this exposure are severe. Competitors could reverse-engineer proprietary technology, and hackers might exploit vulnerabilities in vehicle systems. Additionally, exposed API keys could lead to unauthorized data access, service disruptions, and misuse of the company's infrastructure.

RedHunt Labs also raises concerns about potential legal violations, such as GDPR infringement if customer data was present in the exposed repositories. However, the exact contents of the files remain unverified.

Cibera VPN Team