Описание
@nuxtlabs/github-module made Use of Hard-coded Credentials
https://nuxt.com had a hardcoded GitHub token in the source code of the page. This token had access to multiple repositories under nuxt, nuxtlabs and nuxt-themes GitHub organizations. A patch in version 1.6.2 fixed the issue.
Пакеты
Наименование
@nuxtlabs/github-module
npm
Затронутые версииВерсия исправления
< 1.6.2
1.6.2
Связанные уязвимости
CVSS3: 9.8
nvd
почти 3 года назад
Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.