PT-2018-4706 · Github · Grunt-Gh-Pages

Boennemann

·

Publicado

2018-05-31

·

Atualizado

2019-10-09

·

CVE-2016-10526

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions grunt-gh-pages versions prior to 0.10.0
Description The issue concerns the exposure of GitHub credentials in certain deployment scenarios. In setups where a GitHub token is directly injected into the URL for authentication, the token may be outputted as part of the logging function in affected versions, potentially compromising the credentials if the logs are publicly accessible.
Recommendations For versions prior to 0.10.0, update to version 0.10.0 or later.

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-10526
GHSA-RRJ3-QMH8-72PF

Produtos afetados

Grunt-Gh-Pages