The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.
https://deneyed.com/blog/avalara/
https://appexchange.salesforce.com/appxListingDetail?listingId=a0N3A00000FKAoOUAX