A developer pushes an application to production. The application receives a webhook over HTTPS without a secret. The webhook information contains credentials to service in cleartext. When the information is received, it is stored in the database with an SHA-256 hash. Credentials to the database are accessed at runtime through the use of a vault service. While troubleshooting, the developer sets the logging to debug to view the message from the webhook. What is the security issue in this scenario?
intheshadows00
11 months, 3 weeks agoOmniumdolour
2 months, 3 weeks agortg2123
1 year, 9 months agonunyabeez
1 year, 10 months agomellohello
1 year, 11 months agoaplicacion101
2 years, 3 months agoAngryeyebrows
2 years, 4 months agoMedusa8
2 years, 4 months agoXerAR
2 years, 5 months agoshtou
2 years, 5 months agomacxsz
2 years, 6 months agoSierraSix
2 years, 4 months ago