CVE-2023-36817
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2023-36817: Sensitive information exposure in `tktchurch/website` project leads to potential financial losses and privacy violations. In version 0.1.0, a Stripe API key was accidentally committed and exposed in the public code repository of The King's Temple Church website. An unauthorized party gaining access to this key could carry out transactions on behalf of the organization and access customer information, posing legal implications. The maintainers will revoke the leaked key, generate a new one, and avoid committing keys to the codebase in the future.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.