PT-2018-4706 · Github · Grunt-Gh-Pages

Boennemann

·

Published

2018-05-31

·

Updated

2019-10-09

·

CVE-2016-10526

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions grunt-gh-pages versions prior to 0.10.0
Description The issue concerns the exposure of GitHub credentials in certain deployment scenarios. In setups where a GitHub token is directly injected into the URL for authentication, the token may be outputted as part of the logging function in affected versions, potentially compromising the credentials if the logs are publicly accessible.
Recommendations For versions prior to 0.10.0, update to version 0.10.0 or later.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10526
GHSA-RRJ3-QMH8-72PF

Affected Products

Grunt-Gh-Pages