CVE-2016-10526
—CVSS 3.0
8.6 high
EPSS
2%p75
Published
()
Modified
Description
A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the grunt tasks logging function. If this output is publicly available then the credentials should be considered compromised.
- Vendors
- grunt-gh-pages project
- Products
- grunt-gh-pages
- Weakness
- CWE-391, CWE-255, CWE-532
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.