← Back to CVE List

CVE-2016-10526

Published: 2018-05-31T20:29Z
Last Modified: 2024-11-21T02:44Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the grunt tasks logging function. If this output is publicly available then the credentials should be considered compromised. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt