Secret disclosure when containing characters that become URI encoded
High severity
GitHub Reviewed
Published
Nov 16, 2020
in
semantic-release/semantic-release
•
Updated Jan 9, 2023
Description
Reviewed
Nov 18, 2020
Published to the GitHub Advisory Database
Nov 18, 2020
Last updated
Jan 9, 2023
Impact
Secrets that would normally be masked by
semantic-release
can be accidentally disclosed if they contain characters that become encoded when included in a URL.Patches
Fixed in v17.2.3
Workarounds
Secrets that do not contain characters that become encoded when included in a URL are already masked properly.
References