QID 983893
QID 983893: Nodejs (npm) Security Update for aegir (GHSA-6xhf-x49c-m5m6)
Affected versions of `aegir` bundle and publish the current users github token to npm when `aegir-release` is executed. ## Recommendation Update to version 12.0.8 or later. If you used this module to do a release for your project you should invalidate the GitHub tokens that were leaked.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6xhf-x49c-m5m6 for updates pertaining to this vulnerability.
Vendor References
- GHSA-6xhf-x49c-m5m6 -
github.com/advisories/GHSA-6xhf-x49c-m5m6
CVEs related to QID 983893
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6xhf-x49c-m5m6 | aegir |
|