T09 · Insecure Skill Coding Practices
- Location
yingdao_api.py:47- Finding
Long-Lived API Secret Transmitted in a URL Query String
- Content
View full analysis
Vulnerability Details
File Location:
yingdao_api.py:47-52
Vulnerability Type: Sensitive credential exposure through URL parameters
Risk Level: MediumVulnerable Code
python params = { "accessKeyId": self.access_key_id, "accessKeySecret": self.access_key_secret } resp = requests.get(self.AUTH_ENDPOINT, params=params, timeout=30)Technical Analysis
The authentication request includes
accessKeySecretas a GET query parameter. Although the endpoint uses HTTPS and therefore encrypts the request in transit, URL query strings are commonly retained in web-server access logs, reverse-proxy logs, monitoring systems, debugging output, and request traces.Additionally, network exceptions generated by the HTTP client may contain the requested URL. Since the surrounding exception handler incorporates the exception text into a new
YingdaoError, credential-bearing URL information could be exposed to application logs if callers record that exception.The access key secret is a long-lived credential used to obtain bearer tokens. It therefore requires stronger protection than a temporary access token.
Attack Path
- A user configures valid
YINGDAO_ACCESS_KEY_IDandYINGDAO_ACCESS_KEY_SECRETcredentials. - The client calls
_refresh_token()to authenticate. - The HTTP client serializes both credentials into the request URL.
- An API gateway, reverse proxy, observability platform, debug logger, or error-reporting system records the complete URL.
- An attacker or unauthorized operator with access to those records extracts the access key ID and secret.
- The attacker submits the credentials to the Yingdao authentication endpoint and obtains an access token.
- Using the resulting token, the attacker invokes business APIs within the permissions assigned to the compromised Yingdao credentials.
Impact Assessment
Successful exploitation exposes the Yingdao access key pair. An attacker could authenticate as the affect ...[truncated 486 chars]
- A user configures valid
- Remediation
View remediation
Remediation Suggestions
- Prefer an authentication mechanism that transmits the secret in an authorization header or POST body rather than in the URL, if the Yingdao API supports one.
- If the upstream API mandates GET query parameters:
- Configure clients, proxies, gateways, and servers to redact
accessKeyIdandaccessKeySecret. - Disable request URL logging for the authentication endpoint.
- Ensure application performance monitoring and error-reporting systems do not capture query strings.
- Restrict access to operational logs and define short retention periods.
- Configure clients, proxies, gateways, and servers to redact
- Avoid returning raw
requestsexception text when a request may contain credentials. Raise a sanitized error that omits URLs and query parameters. - Store credentials in an approved secret manager where possible and rotate the access key immediately if URL-bearing logs may already have been retained.
- Use a dedicated, least-privileged Yingdao credential so that exposure does not grant unnecessary task or administrative capabilities.
