Skip to content

Secret disclosure when containing characters that become URI encoded

High
travi published GHSA-r2j6-p67h-q639 Nov 16, 2020

Package

npm semantic-release (npm)

Affected versions

< 17.2.2

Patched versions

17.2.3

Description

Impact

Secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that become encoded when included in a URL.

Patches

Fixed in v17.2.3

Workarounds

Secrets that do not contain characters that become encoded when included in a URL are already masked properly.

Severity

High

CVE ID

CVE-2020-26226

Weaknesses

No CWEs

Credits