Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-32770

Опубликовано: 15 июл. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Gatsby is a framework for building websites. The gatsby-source-wordpress plugin prior to versions 4.0.8 and 5.9.2 leaks .htaccess HTTP Basic Authentication variables into the app.js bundle during build-time. Users who are not initializing basic authentication credentials in the gatsby-config.js are not affected. A patch has been introduced in gatsby-source-wordpress@4.0.8 and gatsby-source-wordpress@5.9.2 which mitigates the issue by filtering all variables specified in the auth: { } section. Users that depend on this functionality are advised to upgrade to the latest release of gatsby-source-wordpress, run gatsby clean followed by a gatsby build. One may manually edit the app.js file post-build as a workaround.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gatsbyjs:gatsby-source-wordpress:*:*:*:*:*:node.js:*:*
Версия до 4.0.8 (исключая)
cpe:2.3:a:gatsbyjs:gatsby-source-wordpress:*:*:*:*:*:node.js:*:*
Версия от 5.0.0 (включая) до 5.9.2 (исключая)

EPSS

Процентиль: 47%
0.00238
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200
CWE-522

Связанные уязвимости

CVSS3: 7.5
debian
больше 4 лет назад

Gatsby is a framework for building websites. The gatsby-source-wordpre ...

CVSS3: 7.5
github
больше 4 лет назад

Basic-auth app bundle credential exposure in gatsby-source-wordpress

EPSS

Процентиль: 47%
0.00238
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200
CWE-522