unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line arguments including --email and --password are output via JSON.stringify without sanitization, exposing secrets to shell history, CI/CD logs, and log aggregation systems. This vulnerability is fixed in 1.8.2.
{
"binaries": [
{
"binary_name": "libunity-core-6.0-9",
"binary_version": "7.4.5+16.04.20190312-0ubuntu1"
},
{
"binary_name": "libunity-core-6.0-dev",
"binary_version": "7.4.5+16.04.20190312-0ubuntu1"
},
{
"binary_name": "unity",
"binary_version": "7.4.5+16.04.20190312-0ubuntu1"
},
{
"binary_name": "unity-autopilot",
"binary_version": "7.4.5+16.04.20190312-0ubuntu1"
},
{
"binary_name": "unity-schemas",
"binary_version": "7.4.5+16.04.20190312-0ubuntu1"
},
{
"binary_name": "unity-services",
"binary_version": "7.4.5+16.04.20190312-0ubuntu1"
}
]
}{
"binaries": [
{
"binary_name": "libunity-core-6.0-9",
"binary_version": "7.5.0+18.04.20190304-0ubuntu1"
},
{
"binary_name": "libunity-core-6.0-dev",
"binary_version": "7.5.0+18.04.20190304-0ubuntu1"
},
{
"binary_name": "unity",
"binary_version": "7.5.0+18.04.20190304-0ubuntu1"
},
{
"binary_name": "unity-autopilot",
"binary_version": "7.5.0+18.04.20190304-0ubuntu1"
},
{
"binary_name": "unity-schemas",
"binary_version": "7.5.0+18.04.20190304-0ubuntu1"
},
{
"binary_name": "unity-services",
"binary_version": "7.5.0+18.04.20190304-0ubuntu1"
}
]
}{
"binaries": [
{
"binary_name": "libunity-core-6.0-9",
"binary_version": "7.5.1+20.04.20211026.1-0ubuntu1"
},
{
"binary_name": "libunity-core-6.0-dev",
"binary_version": "7.5.1+20.04.20211026.1-0ubuntu1"
},
{
"binary_name": "unity",
"binary_version": "7.5.1+20.04.20211026.1-0ubuntu1"
},
{
"binary_name": "unity-autopilot",
"binary_version": "7.5.1+20.04.20211026.1-0ubuntu1"
},
{
"binary_name": "unity-schemas",
"binary_version": "7.5.1+20.04.20211026.1-0ubuntu1"
},
{
"binary_name": "unity-services",
"binary_version": "7.5.1+20.04.20211026.1-0ubuntu1"
}
]
}{
"binaries": [
{
"binary_name": "libunity-core-6.0-9",
"binary_version": "7.5.1+22.04.20211026.2-0ubuntu1"
},
{
"binary_name": "libunity-core-6.0-dev",
"binary_version": "7.5.1+22.04.20211026.2-0ubuntu1"
},
{
"binary_name": "unity",
"binary_version": "7.5.1+22.04.20211026.2-0ubuntu1"
},
{
"binary_name": "unity-autopilot",
"binary_version": "7.5.1+22.04.20211026.2-0ubuntu1"
},
{
"binary_name": "unity-schemas",
"binary_version": "7.5.1+22.04.20211026.2-0ubuntu1"
},
{
"binary_name": "unity-services",
"binary_version": "7.5.1+22.04.20211026.2-0ubuntu1"
}
]
}{
"binaries": [
{
"binary_name": "libunity-core-6.0-9",
"binary_version": "7.7.0+23.04.20230222.2-0ubuntu7"
},
{
"binary_name": "libunity-core-6.0-dev",
"binary_version": "7.7.0+23.04.20230222.2-0ubuntu7"
},
{
"binary_name": "unity",
"binary_version": "7.7.0+23.04.20230222.2-0ubuntu7"
},
{
"binary_name": "unity-autopilot",
"binary_version": "7.7.0+23.04.20230222.2-0ubuntu7"
},
{
"binary_name": "unity-schemas",
"binary_version": "7.7.0+23.04.20230222.2-0ubuntu7"
},
{
"binary_name": "unity-services",
"binary_version": "7.7.0+23.04.20230222.2-0ubuntu7"
},
{
"binary_name": "unity-uwidgets",
"binary_version": "7.7.0+23.04.20230222.2-0ubuntu7"
}
]
}{
"binaries": [
{
"binary_name": "libunity-core-6.0-9",
"binary_version": "7.7.0+23.04.20230222.2-0ubuntu8"
},
{
"binary_name": "libunity-core-6.0-dev",
"binary_version": "7.7.0+23.04.20230222.2-0ubuntu8"
},
{
"binary_name": "unity",
"binary_version": "7.7.0+23.04.20230222.2-0ubuntu8"
},
{
"binary_name": "unity-autopilot",
"binary_version": "7.7.0+23.04.20230222.2-0ubuntu8"
},
{
"binary_name": "unity-schemas",
"binary_version": "7.7.0+23.04.20230222.2-0ubuntu8"
},
{
"binary_name": "unity-services",
"binary_version": "7.7.0+23.04.20230222.2-0ubuntu8"
},
{
"binary_name": "unity-uwidgets",
"binary_version": "7.7.0+23.04.20230222.2-0ubuntu8"
}
]
}