A credential stored in a plugin step's unsecure configuration
What it is
Plugin step has a secret embedded in unsecure configuration.
Why it matters
A credential sits in a plugin step's unsecure config, readable by anyone who can read the registration and carried into solution exports and source control. Pathix reports the pattern and a redacted length, never the value.
Find it yourself
Read the unsecure configuration of every plugin step in the Plugin Registration Tool and look for credential-shaped values: keys, tokens, connection strings, passwords. Remember that unsecure configuration travels in solution exports, so it is also worth searching any exported solution you have in source control.
How to fix it
Move it to Azure Key Vault via an environment variable, and rotate the exposed credential.
Related controls
These mappings are indicative. Pathix detects a condition relevant to a control. It does not certify your compliance, and a finding is not an audit opinion. You stay responsible for your control environment.
Pathix checks this across every environment you scan, along with 39 other conditions. Self-hosted in your own Azure, read-only, metadata-only.