Sensitive Data: Exposed JSON Configuration Files¶
Identifier:
config_json_exposure_fuzz
Scanner Support¶
| GraphQL Scanner | REST Scanner | WebApp Scanner | ASM Scanner | Automated Pentest |
|---|---|---|---|---|
Description¶
Exposed JSON configuration files can contain sensitive information including API keys, access tokens, AWS credentials, database configurations, and application settings that shouldn't be publicly accessible.
How we test: We test for exposed JSON configuration files by attempting to access common configuration file paths and analyzing responses to detect if sensitive configuration data is exposed.
Configuration¶
Example¶
Example configuration:
Reference¶
skip¶
Type: boolean
Skip the test if true.