Cyber Security

A mishandled GitHub token exposed Mercedes-Benz source code

0

A mishandled GitHub token gave unrestricted access to Mercedes-Benz’s internal GitHub Enterprise Service, exposing sensitive internal data including source code to the public.

Like many modern automakers, Mercedes-Benz uses software in its vehicles and services, including safety and control systems, infotainment, autonomous driving, diagnostic and maintenance tools, connectivity and telematics, and electric power and battery management (for EVs).

On September 29, 2023, the researchers at RedHunt Labs discovered a GitHub token in a public repository belonging to a Mercedes employee that gave access to the company’s internal GitHub Enterprise Server.

The GitHub token gave ‘unrestricted’ and ‘unmonitored’ access to the entire source code hosted at the Internal GitHub Enterprise Server. The incident laid bare sensitive repositories including a wealth of intellectual property, and the compromised information included database connection strings, cloud access keys, blueprints, design documents, SSO passwords, API keys, and other critical internal information.

The consequences of publicly exposing that data can be severe. Source code leaks can lead to competitor reverse-engineering proprietary technology or hackers scrutinizing it for potential vulnerabilities in vehicle systems.

Also, the exposure of API keys could lead to unauthorized data access, service disruption, and abuse of the company’s infrastructure for malicious purposes.

The researchers also mention the possibility of legal violations, such as GDPR infringement, in case the exposed repositories contained customer data. However, the researchers have not validated the contents of the exposed files.

Mercedes-Benz was informed of the token leak on January 22, 2024, and revoked it two days later, blocking access to anyone holding and abusing it.

Mercedes declined to say whether it is aware of any third-party access to the exposed data or whether the company has the technical ability, such as access logs, to determine if there was any improper access to its data repositories

Also, the firm has said they are open to working with researchers worldwide and accepts security reports through its vulnerability disclosure program.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Schneider Electric hit by Cactus ransomware attack

Previous article

Police disrupt Grandoreiro banking malware operation

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *