gcp-datastream-servicenow-password-input

A ServiceNow connection profile can carry a user's plaintext password.

gcpcritical service: gcp:datastream emits ContainsCredential

Where it sits

locationdatastream.projects.locations.connectionProfiles.create/datastream.projects.locations.connectionProfiles.patch.request.serviceNowProfile.userPasswordCredentials.password
location kindsecret_value
data kindspassword credential
emits edgeContainsCredential
serviceDatastream / Data Fusion (gcp:datastream)

Collection recipe

access modewrite_only_input
operationdatastream.projects.locations.connectionProfiles.create/datastream.projects.locations.connectionProfiles.patch
response pathrequest.serviceNowProfile.userPasswordCredentials.password
encodingstring
params{"name": "\u003cresource-name\u003e"}

Required permissions

datastream.connectionProfiles.create
datastream.connectionProfiles.update

References

move · open · esc close