Beginner FriendlyFoundry
100 EXP
View results
Submission Details
Severity: high
Invalid

Initial password is shared in the project documents causing anyone to see the password

Summary

"myPassword" is shared in the DeployPasswordStore.s.sol script.

Vulnerability Details

The initial password which will be set with the help of deploy script DeployPasswordStore.s.sol is already shared in the project github.

Impact

Since the git repository is public, everyone has access to the project documents. This allows everyone to see the initial password which will be set during the deployment of the contract.

Tools Used

  • Github

  • Manual audit

Recommendations

Sensitive data should not be recorded in git repositories even if the repository is private.

Updates

Lead Judging Commences

inallhonesty Lead Judge
almost 2 years ago
inallhonesty Lead Judge almost 2 years ago
Submission Judgement Published
Invalidated
Reason: Other

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.