Skip to content

Sensitive Data Exposure in seneca

Low severity GitHub Reviewed Published Sep 11, 2019 to the GitHub Advisory Database • Updated Jan 9, 2023

Package

npm seneca (npm)

Affected versions

< 3.9.0

Patched versions

3.9.0

Description

Versions of seneca prior to 3.9.0 are vulnerable to Sensitive Data Exposure. When a process using the package crashes all environment variables are printed. This may leak sensitive data such as access keys, especially given scenarios when log-monitoring systems store the error output.

Recommendation

Upgrade to version 3.9.0 or later.

References

Reviewed Sep 11, 2019
Published to the GitHub Advisory Database Sep 11, 2019
Last updated Jan 9, 2023

Severity

Low

EPSS score

0.097%
(42nd percentile)

Weaknesses

CVE ID

CVE-2019-5483

GHSA ID

GHSA-2xwv-3cc9-fp7c

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.