PT-2018-6254 · Github · Aegir

Published

2018-06-07

·

Updated

2019-10-09

·

CVE-2017-16225

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: aegir versions 12.0.0 through 12.0.7
Description: The issue concerns aegir, a module for automating JavaScript project management. Affected versions of aegir bundle and publish the current user's GitHub token to npm when aegir-release is executed. This results in the leakage of the GitHub token used by the user who performed the aegir-release.
Recommendations: Update to version 12.0.8 or later. If you used this module to do a release for your project, you should invalidate the GitHub tokens that were leaked.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-16225
GHSA-6XHF-X49C-M5M6

Affected Products

Aegir