Vulnerabilities/

Basic-auth app bundle credential exposure in gatsby-source-wordpress

Severity:
High

Description

The gatsby-source-wordpress plugin prior to versions 4.0.8 and 5.9.2 leaks .htaccess HTTP Basic Authentication variables into the app.js bundle during build-time. Users who are not initializing basic authentication credentials in the gatsby-config.js are not affected.

Recommendation

Update the gatsby-source-wordpress package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
gatsby-source-wordpress
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing