important · Supply chain
Public Docker Hub image layers exposed live operational credentials.
Affects
Public Docker Hub images published under Apache, GitLab, Okteto-related, SAP, and Toradex namespaces, with credentials authorizing access to external cloud services.
Unauthenticated image pulls exposed credentials for Apache GitHub, Okteto Terraform, Toradex Slack, GitLab CI and an OpenAI account; validation found administrative or write-capable access among the strongest cases.
Detail and 7 sources
Sources
ResearchResources | BinarlyVendorExposed GitHub Personal Access Token in Apache Docker Hub image | BinarlyVendorExposed GitHub Personal Access Token in Apache Docker Hub images | BinarlyVendorExposed OpenAI API Key in SAP Docker Hub image | BinarlyVendorExposed GitLab CI/CD Job Token in GitLab Docker Hub Image | BinarlyVendorExposed HashiCorp Terraform API Token in Docker Hub Image | BinarlyVendorExposed Slack Bot and App Tokens with Access to Toradex Workspace | Binarly