Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4qrm-9h4r-v2fx

Опубликовано: 03 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Tina search token leak via lock file in TinaCMS

Impact

Tina search token leaked via lock file (tina-lock.json) in TinaCMS. Sites building with @tinacms/cli < 1.6.2 that use a search token are impacted.

If your Tina-enabled website has search setup, you should rotate that key immediately.

Patches

This issue has been patched in @tinacms/cli@1.6.2

Workarounds

Upgrading, and rotating search token is required for the proper fix.

References

https://github.com/tinacms/tinacms/pull/4758

Пакеты

Наименование

@tinacms/cli

npm
Затронутые версииВерсия исправления

< 1.6.2

1.6.2

EPSS

Процентиль: 48%
0.00253
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-200
CWE-312

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search token may be vulnerable to the search token being leaked via lock file (tina-lock.json). Administrators of Tina-enabled websites with search setup should rotate their key immediately. This issue has been patched in @tinacms/cli version 1.6.2. Upgrading and rotating the search token is required for the proper fix.

EPSS

Процентиль: 48%
0.00253
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-200
CWE-312