Skip to content

remove logging of api and app keys#63

Open
sk-ez wants to merge 2 commits intoDataDog:masterfrom
sk-ez:remove-api-keys-logging
Open

remove logging of api and app keys#63
sk-ez wants to merge 2 commits intoDataDog:masterfrom
sk-ez:remove-api-keys-logging

Conversation

@sk-ez
Copy link

@sk-ez sk-ez commented May 12, 2023

What does this PR do?

closes #64 by removing the lambda code where API and APP keys are logged to the AWS CloudWatch Logs, thereby fixing the vulnerability in the Datadog AWS integration CloudFormation templates

Motivation

Would like to avoid situations where unauthorized parties can gain admin access to organizations' datadog platform due to this exposure

@sk-ez
Copy link
Author

sk-ez commented Jun 21, 2023

Are there outstanding concerns preventing the merging of the fix?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Sensitive api and app keys exposed in logs

2 participants