Description
aegir publish and aegir build may leak secrets from environmental variables in the browser bundle published to npm.
Recommendation
Update the aegir package to the latest compatible version. Followings are version details:
- Affected version(s): >= 21.7.0, < 21.10.1
- Patched version(s): 21.10.1
References
Related Issues
- Exposure of Sensitive Information to an Unauthorized Actor in follow-redirects - CVE-2022-0536
- Exposure of Sensitive Information to an Unauthorized Actor in nanoid - CVE-2021-23566
- Exposure of Sensitive Information in simple-get - CVE-2022-0355
- Exposure of Sensitive Information in eventsource - CVE-2022-1650
- Tags:
- npm
- aegir
Anything's wrong? Let us know Last updated on October 10, 2023