CVE-2023-36817

HIGH

tktchurch/website <0.1.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repository of the church's project. This sensitive information was unintentionally committed and subsequently exposed in the codebase. If an unauthorized party gains access to this key, they could potentially carry out transactions on behalf of the organization, leading to financial losses. Additionally, they could access sensitive customer information, leading to privacy violations and potential legal implications. The affected component is the codebase of our project, specifically the file(s) where the Stripe API key is embedded. The key should have been stored securely, and not committed to the codebase. The maintainers plan to revoke the leaked Stripe API key immediately, generate a new one, and not commit the key to the codebase.

References (1)

Core 1
Core References
Mitigation, Third Party Advisory x_refsource_confirm
https://github.com/tktchurch/website/security/advisories/GHSA-x3m6-5hmf-5x3w

Scores

CVSS v3 7.5
EPSS 0.0048
EPSS Percentile 37.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200 CWE-798
Status published
Products (1)
kingstemple/the_king\'s_temple_church_website 0.1.0
Published Jul 03, 2023
Tracked Since Feb 18, 2026