logo

Bitbucket artifact files can leak plaintext authentication secrets

ID: 2981ee93-65ad-5477-be9f-05d969712da1

STIX ID: report--2981ee93-65ad-5477-be9f-05d969712da1

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-05-21

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive summary:** Mandiant discovered that Bitbucket Pipelines artifact objects can inadvertently contain secured variables (including AWS authentication secrets) in plaintext when developers export environment variables or misconfigure bitbucket-pipelines.yml; such artifacts published or accessible publicly have been used by threat actors to breach AWS accounts. The report outlines the exposure vector, examples of how secrets are leaked to artifact files, mitigation advice (use dedicated secret managers, review artifacts, enable secret scanning), and Atlassian's response advising best practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.