Information Exposure Affecting @tinacms/cli package, versions <1.6.2


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.06% (31st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-TINACMSCLI-7888172
  • published4 Sept 2024
  • disclosed3 Sept 2024
  • creditmattsbennett

Introduced: 3 Sep 2024

CVE-2024-45391  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade @tinacms/cli to version 1.6.2 or higher.

Overview

@tinacms/cli is a The Tina Cloud CLI can be used to set up your project with Tina Cloud configuration, and run a local version of the Tina Cloud content-api (using your file system's content). For a real-world example of how this is being used checkout the [Tina Cloud St

Affected versions of this package are vulnerable to Information Exposure in the tina-lock.json file. An attacker can access the search token by exploiting the insecure storage of this token in the lock file.

Note: If Tina-enabled website has search setup, rotating search token is required for the proper fix.

References

CVSS Scores

version 4.0
version 3.1