CVE Database
/

CVE-2016-10526

Back to search

CVE-2016-10526

Published: May 31, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the grunt tasks logging function. If this output is publicly available then the credentials should be considered compromised.

VendorProductVersions

HackerOne

grunt-gh-pages node module

affected
<=0.9.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now