Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Tina search token leak via lock file in TinaCMS
Vulnerability Description
Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search token may be vulnerable to the search token being leaked via lock file (tina-lock.json). Administrators of Tina-enabled websites with search setup should rotate their key immediately. This issue has been patched in @tinacms/cli version 1.6.2. Upgrading and rotating the search token is required for the proper fix.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
TinaCMS 安全漏洞
Vulnerability Description
TinaCMS是一个用于 Markdown、MDX 和 JSON 的开源无头 CMS。 TinaCMS 1.6.2之前版本存在安全漏洞,该漏洞源于搜索令牌可能通过锁文件泄露。
CVSS Information
N/A
Vulnerability Type
N/A