The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.
How easy to exploit
Severity of consequences
Likelihood of exploitation in next 30 days