id: contentful-token info: name: Contentful Delivery API Token author: DhiyaneshDK severity: info reference: - https://github.com/returntocorp/semgrep-rules/blob/develop/generic/secrets/gitleaks/contentful-delivery-api-token.yaml - https://github.com/returntocorp/semgrep-rules/blob/develop/generic/secrets/gitleaks/contentful-delivery-api-token.go metadata: verified: true max-request: 1 tags: contentful,exposure,tokens http: - method: GET path: - "{{BaseURL}}" extractors: - type: regex part: body regex: - (?i)(?:contentful)(?:[0-9a-z\-_\t .]{0,20})(?:[\s|']|[\s|"]){0,3}(?:=|>|:=|\|\|:|<=|=>|:)(?:'|\"|\s|=|\x60){0,5}([a-z0-9=_\-]{43})(?:['|\"|\n|\r|\s|\x60|;]|$) # digest: 490a00463044022006e3e03103bf929fd43d2e6c63686f3c316839b8dd200b3436d8d4f422be422e02202452e6f8e53cc6a454588e1157d8b05384c8d6a895de5802a5bc5de9805c7b37:922c64590222798bb761d5b6d8e72950