GHSA-qfcv-5whw-7pcw

Suggest an improvement
Source
https://github.com/advisories/GHSA-qfcv-5whw-7pcw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-qfcv-5whw-7pcw/GHSA-qfcv-5whw-7pcw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qfcv-5whw-7pcw
Aliases
Published
2020-05-27T21:09:15Z
Modified
2026-09-10T03:48:46Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Exposure of Sensitive Information to an Unauthorized Actor in AEgir
Details

Impact

aegir publish and aegir build may leak secrets from environmental variables in the browser bundle published to npm.

Patches

The code has been patched, users should upgrade to >= 21.10.1

Workarounds

Run printenv to check your environment variables and revoke any secrets.

For more information

If you have any questions or comments about this advisory:

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-05-27T21:08:38Z",
    "nvd_published_at": "2020-05-27T21:15:00Z",
    "severity": "CRITICAL"
}
References

Affected packages

npm / aegir

Package

Affected ranges

Type
SEMVER
Events
Introduced
21.7.0
Fixed
21.10.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-qfcv-5whw-7pcw/GHSA-qfcv-5whw-7pcw.json"