Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rrj3-qmh8-72pf

Опубликовано: 18 фев. 2019
Источник: github
Github: Прошло ревью

Описание

grunt-gh-pages before 0.10.0 may allow unencrypted GitHub credentials to be written to a log file

Versions of grunt-gh-pages prior to 0.10.0 are affected by a vulnerability which may cause unencrypted GitHub credentials to be written to a log file in certain circumstances.

In the grunt-gh-pages deployment scenario where authentication is performed by injecting a GitHub token directly into the auth portion of the URL, grunt-gh-pages will write the token to a log file, unencrypted.

Recommendation

Update to version 0.10.0 or later.

Пакеты

Наименование

grunt-gh-pages

npm
Затронутые версииВерсия исправления

<= 0.9.1

0.10.0

EPSS

Процентиль: 53%
0.003
Низкий

Дефекты

CWE-391

Связанные уязвимости

CVSS3: 8.6
nvd
больше 7 лет назад

A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the grunt tasks logging function. If this output is publicly available then the credentials should be considered compromised.

EPSS

Процентиль: 53%
0.003
Низкий

Дефекты

CWE-391