Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2j6-p67h-q639

Опубликовано: 18 нояб. 2020
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Secret disclosure when containing characters that become URI encoded

Impact

Secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that become encoded when included in a URL.

Patches

Fixed in v17.2.3

Workarounds

Secrets that do not contain characters that become encoded when included in a URL are already masked properly.

Пакеты

Наименование

semantic-release

npm
Затронутые версииВерсия исправления

<= 17.2.2

17.2.3

EPSS

Процентиль: 57%
0.0035
Низкий

8.1 High

CVSS3

Дефекты

CWE-116

Связанные уязвимости

CVSS3: 8.1
nvd
около 5 лет назад

In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded when included in a URL are already masked properly. The issue is fixed in version 17.2.3.

EPSS

Процентиль: 57%
0.0035
Низкий

8.1 High

CVSS3

Дефекты

CWE-116