Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-2138: fix: do not expose token in public runtime config (#41) · nuxtlabs/github-module@5490c43

Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.

CVE
#git#hard_coded_credentials

@@ -69,7 +69,6 @@ export default defineNuxtModule<ModuleOptions>({ owner: options.owner || process.env.GITHUB_OWNER, branch: options.branch || process.env.GITHUB_BRANCH, repo: options.repo || process.env.GITHUB_REPO, token: options.token || process.env.GITHUB_TOKEN, disableCache: options.disableCache, parseContents: options.parseContents, maxContributors: options.maxContributors @@ -79,7 +78,9 @@ export default defineNuxtModule<ModuleOptions>({ // @ts-ignore nuxt.options.runtimeConfig.public.github = defu(nuxt.options.runtimeConfig.public.github, config) // @ts-ignore nuxt.options.runtimeConfig.github = defu(nuxt.options.runtimeConfig.github, config) nuxt.options.runtimeConfig.github = defu(nuxt.options.runtimeConfig.github, { token: options.token || process.env.GITHUB_TOKEN }, config)
// Autolink issue/PR/commit links using `remark-github` plugin if (options.remarkPlugin) {

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907