Skip to content

Commit

Permalink
Modify rule S6721: Fix description (#4535)
Browse files Browse the repository at this point in the history
* Fix secret_type being undefined

* Remove Workflow for Teams description, as it is not detected by us

* Add missing empty line
  • Loading branch information
egon-okerman-sonarsource authored Nov 26, 2024
1 parent 81be66c commit e0f73e0
Showing 1 changed file with 2 additions and 5 deletions.
7 changes: 2 additions & 5 deletions rules/S6721/secrets/rule.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -6,12 +6,9 @@ include::../../../shared_content/secrets/rationale.adoc[]

=== What is the potential impact?

Teams Workflow webhook URLs have different effects depending on their
permissions: They can be used only to write Teams posts or to trigger other
workflows.
Below are some real-world scenarios that illustrate the potential impact of an attacker exploiting this secret.

Below are some real-world scenarios that illustrate some impacts of an attacker
exploiting the secret.
:secret_type: webhook

include::../../../shared_content/secrets/impact/phishing.adoc[]

Expand Down

0 comments on commit e0f73e0

Please sign in to comment.