Application security, Identity, Third-party code

Extensive public GitLab repository secret exposure uncovered

(Credit: monticellllo – stock.adobe.com)

BleepingComputer reports that over 17,000 secrets have been leaked by public repositories on the web-based Git platform GitLab Cloud, which is almost threefold more than those exposed by Bitbucket repositories.

Most of the 17,430 verified live secrets were more recent than 2018, but secrets from 2009 continued to be valid, according to researcher Luke Marshall. Google Cloud Platform credentials accounted for the bulk of the secrets, followed by MongoDB keys, Telegram bot tokens, and OpenAI keys, said Marshall, who leveraged a GitLab public API endpoint to facilitate public repository enumeration and later used the open-source TruffleHog tool to determine sensitive information from repository code.

"Each Lambda invocation executed a simple TruffleHog scan command with concurrency set to 1000. This setup allowed me to complete the scan of 5,600,000 repositories in just over 24 hours," Marshall added. All affected parties have been informed about exposed secrets with the assistance of Claude Sonnet 3.7.

You can skip this ad in 5 seconds