@nuxtlabs/github-module made Use of Hard-coded Credentials
Critical severity
GitHub Reviewed
Published
Apr 18, 2023
to the GitHub Advisory Database
•
Updated Nov 12, 2023
Description
Published by the National Vulnerability Database
Apr 18, 2023
Published to the GitHub Advisory Database
Apr 18, 2023
Reviewed
Apr 21, 2023
Last updated
Nov 12, 2023
https://nuxt.com had a hardcoded GitHub token in the source code of the page. This token had access to multiple repositories under
nuxt
,nuxtlabs
andnuxt-themes
GitHub organizations. A patch in version 1.6.2 fixed the issue.References