BlueXP darksite installer contains AWS S3 keys and secrets stored in a file
Applies to
- BlueXP ( formerly Cloud Manager)
- Darksite deployment
Issue
Penetration test run against a darksite connector deployment returns the security risk below:
"Exposure of Sensitive Information to an Unauthorized Actor. The cloud connector image Cloud-Manager-Connector-offline-v3.9.26 contains AWS keys and secrets that belong to NetApp. They give access to the an AWS environment owned by NetApp"