Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Renovate 19.180.0 before 23.25.1 Token Leakage via Logs
Vulnerability Description
Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction. Anyone with access to saved logs could obtain the bot credentials. Fixed in 23.25.1; Azure DevOps users should revoke and regenerate credentials if logs may have been exposed.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过日志文件的信息暴露
Vulnerability Title
Renovate Bot Renovate 日志信息泄露漏洞
Vulnerability Description
Renovate Bot Renovate是Renovate Bot组织的一个自动化依赖更新工具。 Renovate Bot Renovate 19.180.0版本至23.25.1之前版本存在日志信息泄露漏洞,该漏洞源于git http.extraheader=AUTHORIZATION参数未脱敏记录,可能导致授权令牌泄露。
CVSS Information
N/A
Vulnerability Type
N/A