-
Notifications
You must be signed in to change notification settings - Fork 2
Description
CVE-2020-26226 - High Severity Vulnerability
Vulnerable Library - semantic-release-4.3.5.tgz
automated semver compliant package publishing
Library home page: https://registry.npmjs.org/semantic-release/-/semantic-release-4.3.5.tgz
Path to dependency file: /justapis-javascript-sdk/package.json
Path to vulnerable library: /justapis-javascript-sdk/node_modules/semantic-release/package.json
Dependency Hierarchy:
- ❌ semantic-release-4.3.5.tgz (Vulnerable Library)
Vulnerability Details
In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded when included in a URL are already masked properly. The issue is fixed in version 17.2.3.
Publish Date: 2020-11-18
URL: CVE-2020-26226
CVSS 3 Score Details (8.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: GHSA-r2j6-p67h-q639
Release Date: 2020-11-18
Fix Resolution: 17.2.3
⛑️ Automatic Remediation is available for this issue