Skip to content

aegir publish may leak secrets in environment variables

Critical
hugomrdias published GHSA-qfcv-5whw-7pcw May 22, 2020

Package

npm aegir (npm)

Affected versions

>= 21.7.0

Patched versions

21.10.1

Description

Impact

aegir publish and aegir build may leak secrets from environmental variables in the browser bundle published to npm.

Patches

The code has been patched, users should upgrade to >=21.10.1

Workarounds

Run printenv to check your environment variables and revoke any secrets.

For more information

If you have any questions or comments about this advisory:

Severity

Critical

CVE ID

CVE-2020-11059

Weaknesses

No CWEs