Exposure DB

1,048 exposure sites - every place a customer-controlled credential or secret can leak - each mapped to the edge it emits, its collection recipe, and what leaks.

406
aws
377
azure
265
gcp
563
critical severity
250
medium severity
233
high severity
2
low severity

1,048 site(s) · page 21 of 21

iamcredentials.projects.serviceAccounts.signJwt.signedJwt - leaks credential, signing_secret
Git upload-pack/archive.commits, trees, blobs, and file bytes - leaks source_code_secret, credential, private_key, password, api_key
gcpcriticalCanReadData
sourcerepo.projects.repos.get.{name,url} - leaks sensitive_data
spanner.projects.instances.databases.getDdl.statements[] - leaks credential, sensitive_data
spanner.projects.instances.get.labels.<value> - leaks credential, api_key, sensitive_data, pii
spanner.projects.instances.databases.sessions.read.rows[] - leaks credential, customer_data, pii, sensitive_data
gcpcriticalCanReadData
spanner.projects.instances.databases.sessions.executeSql.rows[] - leaks credential, customer_data, pii, sensitive_data
gcpcriticalCanReadData
cloudtasks.projects.locations.queues.tasks.get.appEngineHttpRequest.{body,headers.<value>,relativeUri} - leaks credential, customer_data, pii, sensitive_data
gcpcriticalCanReadData
cloudtasks.projects.locations.queues.tasks.get.httpRequest.body - leaks credential, customer_data, pii, sensitive_data
gcpcriticalCanReadData
cloudtasks.projects.locations.queues.tasks.get.httpRequest.{url,headers.<value>} - leaks credential, api_key, oauth_token, sensitive_data
aiplatform.projects.locations.cachedContents.create.request.{contents[],systemInstruction} - leaks credential, password, api_key, oauth_token, customer_data, pii, sensitive_data
aiplatform.projects.locations.cachedContents.create.request.tools[].{exaAiSearch.apiKey,parallelAiSearch.apiKey,retrieval.externalApi.apiAuth.apiKeyConfig.apiKeyString,retrieval.externalApi.authConfig.apiKeyConfig.apiKeyString,retrieval.externalApi.authConfig.oauthConfig.accessToken,retrieval.externalApi.authConfig.oidcConfig.idToken} - leaks api_key, oauth_token, bearer_token, credential
aiplatform.projects.locations.customJobs.get.jobSpec.workerPoolSpecs[].containerSpec.{command[],args[]} - leaks credential, password, api_key, access_key, secret_key, oauth_token, sensitive_data
aiplatform.projects.locations.customJobs.get.jobSpec.workerPoolSpecs[].containerSpec.env[].value - leaks credential, password, api_key, access_key, secret_key, oauth_token, connection_string
aiplatform.projects.locations.customJobs.get.jobSpec.workerPoolSpecs[].pythonPackageSpec.env[].value - leaks credential, password, api_key, access_key, secret_key, oauth_token, connection_string
aiplatform.projects.locations.featureOnlineStores.featureViews.generateFetchAccessToken.accessToken - leaks access_key, bearer_token, credential
aiplatform.projects.locations.publishers.models.generateContent.request.{contents[].parts[],systemInstruction.parts[],tools[]} - leaks credential, password, api_key, oauth_token, customer_data, pii, sensitive_data
aiplatform.projects.locations.publishers.models.generateContent.candidates[].content.parts[] - leaks credential, customer_data, pii, sensitive_data
gcpcriticalContainsSecret
aiplatform.projects.locations.publishers.models.generateContent.request.tools[].{exaAiSearch.apiKey,parallelAiSearch.apiKey,retrieval.externalApi.apiAuth.apiKeyConfig.apiKeyString,retrieval.externalApi.authConfig.apiKeyConfig.apiKeyString,retrieval.externalApi.authConfig.oauthConfig.accessToken,retrieval.externalApi.authConfig.oidcConfig.idToken} - leaks api_key, oauth_token, bearer_token, credential
aiplatform.projects.locations.models.get.containerSpec.env[].value - leaks credential, password, api_key, access_key, secret_key, oauth_token, connection_string
aiplatform.projects.locations.deploy.request.modelConfig.huggingFaceAccessToken - leaks access_key, bearer_token, credential
Jupyter contents API / mounted filesystem read.notebook cells, outputs, and files - leaks source_code_secret, credential, private_key, customer_data, pii
gcpcriticalCanReadData
aiplatform.projects.locations.notebookRuntimeTemplates.get.softwareConfig.env[].value - leaks credential, password, api_key, access_key, secret_key, oauth_token, connection_string
aiplatform.projects.locations.pipelineJobs.get.runtimeConfig.{parameterValues,inputArtifacts} - leaks credential, customer_data, pii, sensitive_data
gcpcriticalContainsSecret
aiplatform.projects.locations.pipelineJobs.get.pipelineSpec - leaks source_code_secret, credential, password, api_key, private_key, connection_string
aiplatform.projects.locations.ragCorpora.get.vectorDbConfig.apiAuth.apiKeyConfig.apiKeyString - leaks api_key, credential
aiplatform.projects.locations.ragCorpora.ragFiles.import.request.importRagFilesConfig.sharePointSources.sharePointSources[].clientSecret.apiKeyString - leaks secret_key, api_key, credential
aiplatform.projects.locations.reasoningEngines.get.spec.deploymentSpec.env[].value - leaks credential, password, api_key, access_key, secret_key, oauth_token, connection_string
aiplatform.projects.locations.customJobs.get.labels.<value> - leaks credential, api_key, sensitive_data, pii
notebooks.projects.locations.instances.generateAccessToken.access_token - leaks oauth_token, bearer_token, credential
notebooks.projects.locations.instances.get.containerImage.repository/metadata.items or postStartupScript - leaks source_code_secret, credential, password, api_key, private_key
compute.networks.get.description - leaks credential, api_key, sensitive_data, pii
VPC Packet Mirroring collector capture.mirrored packet payloads - leaks credential, oauth_token, customer_data, pii, sensitive_data
gcpcriticalCanReadData
compute.publicAdvertisedPrefixes.get.sharedSecret - leaks password, credential
compute.subnetworks.get.description - leaks credential, api_key, sensitive_data, pii
compute.vpnTunnels.get.sharedSecret - leaks password, encryption_key_material, credential
iam.projects.locations.workloadIdentityPools.get.{displayName,description} - leaks credential, api_key, sensitive_data, pii
iam.projects.locations.workloadIdentityPools.providers.get.attributeCondition - leaks credential, api_key, sensitive_data, pii
iam.projects.locations.workloadIdentityPools.providers.get.attributeMapping - leaks sensitive_data, pii
iam.projects.locations.workloadIdentityPools.providers.get.{oidc.issuerUri,oidc.allowedAudiences[],aws.accountId,saml.idpMetadataXml} - leaks certificate, sensitive_data
iam.locations.workforcePools.providers.create/iam.locations.workforcePools.providers.patch.request.{extendedAttributesOauth2Client,extraAttributesOauth2Client}.clientSecret.value.plainText - leaks oauth_token, secret_key, credential
iam.projects.locations.oauthClients.credentials.create.clientSecret - leaks oauth_token, secret_key, credential
iam.locations.workforcePools.providers.create/iam.locations.workforcePools.providers.patch.request.oidc.clientSecret.value.plainText - leaks oauth_token, secret_key, credential
iam.locations.workforcePools.providers.scimTenants.tokens.create.securityToken - leaks bearer_token, credential
workflowexecutions.projects.locations.workflows.executions.get.{argument,result,error.payload} - leaks credential, customer_data, pii, sensitive_data
gcpcriticalCanReadData
workflows.projects.locations.workflows.get.{description,labels.<value>} - leaks credential, api_key, sensitive_data, pii
workflows.projects.locations.workflows.get.sourceContents - leaks source_code_secret, credential, password, api_key, private_key, connection_string
workflows.projects.locations.workflows.get.userEnvVars.<value> - leaks credential, password, api_key, access_key, secret_key, oauth_token, connection_string
move · open · esc close