Top issues
Detected presence of plaintext credentials within network protocol strings.
Causes risk: web service credentials found
secrets
Problem
Various network communication protocols allow including plaintext authentication credentials. Information such as user names and passwords could be passed through a non-encrypted channel, and therefore intercepted by malicious actors. Credentials are considered secrets, and should be kept encrypted until they are used. This policy control matches the following URI pattern protocol://username:password@domain within any software package component.Prevalence in RubyGems community
6 packages
found in
Top 100
16 packages
found in
Top 1k
69 packages
found in
Top 10k
401 packages
in community
Next steps
Review the reported matches. If the warning refers to a placeholder credential value, it can be safely ignored.
Top behaviors
Contains URLs that contain basic authentication credentials.
network
Prevalence in RubyGems community
Behavior often found in this community (Common)
13 packages
found in
Top 100
54 packages
found in
Top 1k
440 packages
found in
Top 10k
3598 packages
in community
Queries the current Ruby on Rails environment.
search
Prevalence in RubyGems community
Behavior often found in this community (Common)
13 packages
found in
Top 100
58 packages
found in
Top 1k
584 packages
found in
Top 10k
6161 packages
in community
Writes data to the STDOUT stream.
execution
Prevalence in RubyGems community
Behavior often found in this community (Common)
56 packages
found in
Top 100
238 packages
found in
Top 1k
1665 packages
found in
Top 10k
21579 packages
in community
Checks if a file or a directory exists.
file
Prevalence in RubyGems community
Behavior often found in this community (Common)
71 packages
found in
Top 100
371 packages
found in
Top 1k
3584 packages
found in
Top 10k
53830 packages
in community
Concatenates strings.
behavior
Prevalence in RubyGems community
Behavior often found in this community (Common)
67 packages
found in
Top 100
320 packages
found in
Top 1k
2796 packages
found in
Top 10k
30022 packages
in community
Top vulnerabilities
No vulnerabilities found.