CVE-2020-11059 – aegir
Package
Manager: npm
Name: aegir
Vulnerable Version: >=21.7.0 <21.10.1
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00373 pctl0.58192
Details
Exposure of Sensitive Information to an Unauthorized Actor in AEgir ### Impact `aegir publish` and `aegir build` may leak secrets from environmental variables in the browser bundle published to npm. ### Patches The code has been patched, users should upgrade to >= 21.10.1 ### Workarounds Run `printenv` to check your environment variables and revoke any secrets. ### For more information If you have any questions or comments about this advisory: * Open an issue in [aegir](https://github.com/ipfs/aegir)
Metadata
Created: 2020-05-27T21:09:15Z
Modified: 2021-10-08T19:56:28Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-qfcv-5whw-7pcw/GHSA-qfcv-5whw-7pcw.json
CWE IDs: ["CWE-200"]
Alternative ID: GHSA-qfcv-5whw-7pcw
Finding: F038
Auto approve: 1