Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Exposed Kubernetes Secrets 2023: How an SAP Artifact…
Breach analysis Incident: 21 Nov 2023

Exposed Kubernetes Secrets 2023: How an SAP Artifact Repository Key With Access to 95 Million Artifacts Ended Up on GitHub

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 6 min read
Category: NHI
On this page

In November 2023, researchers at Aqua Security's Nautilus team reported that Kubernetes configuration files containing registry credentials had been committed to public GitHub repositories by hundreds of organisations and open-source projects. The credentials were stored in Kubernetes Secrets of the dockercfg and dockerconfigjson types, which hold the username and password a cluster uses to pull container images. Because Kubernetes Secrets are only base64-encoded, anyone who found the files could decode them in one step. Of 438 records that looked like valid registry credentials, 203 worked, usually with both pull and push rights. The most serious case was SAP: Aqua found valid credentials for SAP's artifact repository that gave access to more than 95 million artifacts, with permission to download and to perform limited deploy operations. Aqua reported the finding and said SAP promptly closed the exposure and investigated. No misuse was reported.

Key takeaways

  • Aqua found Kubernetes registry secrets in public GitHub repositories belonging to hundreds of organisations.
  • 203 of 438 candidate records held valid registry credentials, mostly with pull and push rights.
  • One exposed key gave access to SAP's artifact repository of more than 95 million artifacts, with download and limited deploy rights.
  • SAP closed the exposure promptly after Aqua reported it; no misuse was reported.
  • The identity lesson: base64 is not encryption, and a registry credential with push rights is a supply chain key.

At a glance

OrganisationsSAP and hundreds of other organisations and open-source projects; Aqua Security (research)
WhenPublished 21 November 2023
AttackerNone known. Found by researchers
Entry pointKubernetes Secrets with registry credentials committed to public GitHub repositories
Identities abusedContainer registry and artifact repository credentials; none confirmed misused
Impact203 valid registry credentials exposed; SAP artifact repository access to more than 95 million artifacts
CategoryNHI. Incident class: exposure (registry credentials in public repositories, no confirmed misuse)

What happened

Aqua's researchers, Yakir Kadkoda and Assaf Morag, searched GitHub for Kubernetes files containing .dockerconfigjson and .dockercfg entries. "The initial query yielded over 8,000 results, prompting us to refine our search to include only those records that contained user and password values encoded in base64. This refinement led us to 438 records that potentially held valid credentials for registries. Out of these, 203 records, approximately 46%, contained valid credentials that provided access to the respective registries. In the majority of cases, these credentials allowed for both pulling and pushing privileges." SecurityWeek quoted the researchers' explanation of why the secrets were so exposed: they were "merely a single base64 decode command away from being revealed as plaintext secrets."

The SAP case stood out. Aqua wrote: "We discovered valid credentials for the Artifacts repository of SAP SE. These credentials provided access to more than 95 million artifacts, along with permissions for download and limited deploy operations." It described the risk as "the leakage of proprietary code, data breaches, and the risk of supply chain attacks," and said the SAP security team "promptly closed the exposure, conducted an investigation and maintained communication with us." Aqua also found secrets for the registries of two large blockchain companies.

Security Affairs reported further details: some secrets had been exposed for up to five years, weak passwords such as "ChangeMe" and "dockerhub" were in active use, and the secret scanners the researchers tested did not detect the encoded secrets. On the positive side, the AWS and Google Container Registry credentials found were temporary and had already expired.

Timeline

DateEvent
Up to five years before disclosureSome Kubernetes secrets are committed to public repositories, according to Security Affairs.
Before 21 November 2023Aqua reports the SAP credentials; SAP closes the exposure.
21 November 2023Aqua publishes its research.
22 November 2023SecurityWeek reports the findings.

How it happened: the identity attack path

  1. Registry credentials in a Secret. Clusters use dockerconfigjson Secrets to pull private images.
  2. Committed to Git. Kubernetes YAML files, including the Secret, were pushed to public repositories.
  3. Encoded, not encrypted. The base64 values decode directly to usernames and passwords.
  4. Missed by scanners. The encoded secrets were not detected by the tools Aqua tested.
  5. Registry access. Valid credentials gave pull and often push access, including to SAP's artifact repository.

Impact

  • Exposed: 203 valid registry credentials across hundreds of organisations.
  • Largest case: SAP artifact repository access to more than 95 million artifacts, with download and limited deploy rights.
  • Misuse: none reported; SAP closed the exposure after Aqua's report.

What this means for NHI governance

A registry credential is one of the most powerful non-human identities in a delivery pipeline. With push rights, it can replace an image or artifact that thousands of systems will pull and run. This research shows how easily such credentials leave the cluster: a Kubernetes manifest looks like configuration, so it is committed like configuration, and the secret inside looks like random text.

Secrets should never live in manifests in source control. Use external secret stores or sealed secrets, give pull-only credentials to clusters, and scan for encoded as well as plaintext secrets. See our Kubernetes NHI Security Guide and Secrets Management Guide.

Recommendations

Frequently asked questions

Was SAP breached?

No breach was reported. Aqua Security found valid credentials for SAP's artifact repository in a public GitHub repository, and SAP closed the exposure after Aqua reported it.

What did the exposed SAP credentials allow?

Access to more than 95 million artifacts, with permission to download and to perform limited deploy operations, according to Aqua.

Why are Kubernetes Secrets in Git dangerous?

Kubernetes Secrets are base64-encoded, not encrypted, so anyone who sees the file can read the credentials.

Docker Hub Secrets Leak 2025 · PyPI Secrets Exposure 2023 · Kubernetes NHI Security Guide · Secrets Management Guide · CI/CD Pipeline Identity Security Guide

How NHI Mgmt Group can help

Registry credentials can rewrite your software supply chain. We help teams keep them out of source control, scope them tightly and rotate them fast. See our NHI and AI agent security training.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org