9. of Repudiation
An attacker can use a shared key or authenticate as different principals, confusing the information in the logs.
Threat |
|
You have multiple services using the same service account so an attacker can steal the credentials or token of the service account and then use it to access different parts of the system. |
|
CAPEC |
CAPEC-151 - Identity Spoofing CAPEC-195 - Principal Spoof CAPEC-194 - Fake the Source of Data |
ASVS |
2.2.5 - Ensure identity and access management components authenticate with each other via Mutual TLS. 2.10.1 - Ensure service-to-service auth doesn’t use static tokens. 2.10.4 - Ensure secrets are handled and stored securely, and never hardcoded in your applications. |
CWE |
...