PT-2018-6254 · Github · Aegir
Publicado
2018-06-07
·
Atualizado
2019-10-09
·
CVE-2017-16225
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
aegir versions 12.0.0 through 12.0.7
Description:
The issue concerns aegir, a module for automating JavaScript project management. Affected versions of
aegir bundle and publish the current user's GitHub token to npm when aegir-release is executed. This results in the leakage of the GitHub token used by the user who performed the aegir-release.Recommendations:
Update to version 12.0.8 or later.
If you used this module to do a release for your project, you should invalidate the GitHub tokens that were leaked.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Aegir