Context-Inappropriate Capability
Medium
- Confidence
- 99% confidence
- Finding
- The document exposes a hardcoded AES key and concrete internal infrastructure details, including database and Kafka endpoints. Even though this is 'just documentation,' such secrets and topology data materially lower the bar for unauthorized access, lateral movement, and offline decryption of protected configuration values.
