Vulnerabilities/

Sensitive Data Exposure in seneca

Severity:
Low

Description

Versions of seneca prior to 3.9.0 are vulnerable to Sensitive Data Exposure. When a process using the package crashes all environment variables are printed. This may leak sensitive data such as access keys, especially given scenarios when log-monitoring systems store the error output.

Recommendation

Update the seneca package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
seneca
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing