Vulnerabilities/

Exposure of Sensitive Information to an Unauthorized Actor in AEgir

Severity:
High

Description

aegir publish and aegir build may leak secrets from environmental variables in the browser bundle published to npm.

Recommendation

Update the aegir package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
aegir
Anything's wrong? Let us know Last updated on October 10, 2023

This issue is available in SmartScanner Professional

See Pricing