Versions of seneca prior to 3.9.0 are vulnerable to Sensitive Data Exposure. When a process using the package crashes all environment variables are printed. This may leak sensitive data such as access keys, especially given scenarios when log-monitoring systems store the error output.
Upgrade to version 3.9.0 or later.
{
"nvd_published_at": null,
"cwe_ids": [
"CWE-209"
],
"github_reviewed_at": "2019-09-11T22:45:13Z",
"severity": "LOW",
"github_reviewed": true
}