Information Exposure Affecting renovate package, versions >=19.180.0 <23.25.1
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-RENOVATE-674573
- published 15 Sep 2020
- disclosed 14 Sep 2020
- credit Unknown
How to fix?
Upgrade renovate
to version 23.25.1 or higher.
Overview
renovate is a dependency updater.
Affected versions of this package are vulnerable to Information Exposure. The bot's token may be exposed in server or pipeline logs due to the http.extraheader=AUTHORIZATION
parameter being logged without redaction.
Note: This issue applies to Azure DevOps users only.
References
CVSS Scores
version 3.1