43.24.2
9 years ago
2 hours ago
Known vulnerabilities in the renovate package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
renovate is a dependency updater. Affected versions of this package are vulnerable to Improper Removal of Sensitive Information Before Storage or Transfer due to spawned child processes inheriting and not properly filtering environment variables. An attacker can access sensitive environment variables from the calling process from inside child processes. How to fix Improper Removal of Sensitive Information Before Storage or Transfer? Upgrade | >=42.68.1 <42.96.3>=43.0.0 <43.4.4 |