GHSA-rrj3-qmh8-72pf

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/02/GHSA-rrj3-qmh8-72pf/GHSA-rrj3-qmh8-72pf.json
Aliases
  • CVE-2016-10526
Published
2019-02-18T23:39:11Z
Modified
2022-08-03T23:53:09Z
Details

Versions of grunt-gh-pages prior to 0.10.0 are affected by a vulnerability which may cause unencrypted GitHub credentials to be written to a log file in certain circumstances.

In the grunt-gh-pages deployment scenario where authentication is performed by injecting a GitHub token directly into the auth portion of the URL, grunt-gh-pages will write the token to a log file, unencrypted.

Recommendation

Update to version 0.10.0 or later.

References

Affected packages

npm / grunt-gh-pages

grunt-gh-pages

Affected ranges

Type
SEMVER
Events
Introduced
0
Fixed
0.10.0

Affected versions

Database specific

{
    "last_known_affected_version_range": "<= 0.9.1"
}