QID 984044
QID 984044: Nodejs (npm) Security Update for grunt-gh-pages (GHSA-rrj3-qmh8-72pf)
Versions of `grunt-gh-pages` prior to 1.0.0 are affected by a vulnerability which may cause unencrypted github credentials to be written to a log file in certain circumstances. In the `grunt-gh-pages` deployment scenario where authentication is performed by injecting a github token directly into the auth portion of the URL, `grunt-gh-pages` will write the token to a log file, unencrypted. ## Recommendation Update to version 1.0.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rrj3-qmh8-72pf for updates pertaining to this vulnerability.
Vendor References
- GHSA-rrj3-qmh8-72pf -
github.com/advisories/GHSA-rrj3-qmh8-72pf
CVEs related to QID 984044
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rrj3-qmh8-72pf | grunt-gh-pages |
|