High severityJavaHardcoded SecretsMEDIUM confidence
Basic Auth Credentials In URL
HTTP Basic-Auth credentials are embedded directly in a URL literal (scheme://user:pass@host, CWE-798).
Standards mapping
- OWASP ASVS
- V6.4.1 (L2)V2.10.4 (L2)
Vulnerable vs. safe
Flagged by this check
String u = "https://admin:[email protected]/api";Passes - the safe pattern
String ok = "https://intranet.example.com/api";Why it matters & how to fix it
HTTP Basic-Auth credentials are embedded directly in a URL literal (scheme://user:pass@host, CWE-798). The password is exposed in source, logs, proxies, and browser history. Remove credentials from the URL and supply them at request time from externalized configuration, e.g. an Authorization header built from a secret loaded at runtime.
References
Rule ID integsec-java-basic-auth-credentials-in-url - engine: Opengrep - license: MIT - Copyright (c) IntegSec Inc.
TurboPentest runs this check automatically
Connect a GitHub repo and this check runs on every white-box pentest - AI-validated and reported with proof, from $99 per target.
Start a pentestRelated checks
- JavaScript / TypeScript - Hardcoded SecretsBasic Auth Credentials In URL
- JavaScript / TypeScript - Hardcoded SecretsDB Connection String With Credentials
- JavaScript / TypeScript - Hardcoded SecretsHardcoded Credential String
- JavaScript / TypeScript - Hardcoded SecretsHardcoded Crypto Key Or IV
- Python - Hardcoded SecretsBasic Auth Credentials In URL
- Python - Hardcoded SecretsDB Connection String Credentials