{"id":"CVE-2021-21421","aliases":["GHSA-xw22-wv29-3299"],"url":"https://o3.security/vulnerability/CVE-2021-21421","summary":"ApiKey secret could be revelated on network issue","details":"node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client error to the end user will offer api key value too This is fixed in node-etsy-client v0.3.0 and later.","published":"2021-04-01T22:15:11.997Z","modified":"2026-07-09T11:24:04.873032Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"node-etsy-client","fixedVersion":"0.3.0"}],"fix":{"url":"https://github.com/creharmony/node-etsy-client/commit/b4beb8ef080366c1a87dbf9e163051a446acaa7d","label":"creharmony/node-etsy-client@b4beb8e"},"references":[{"type":"ADVISORY","url":"https://github.com/creharmony/node-etsy-client/security/advisories/GHSA-xw22-wv29-3299"},{"type":"FIX","url":"https://github.com/creharmony/node-etsy-client/commit/b4beb8ef080366c1a87dbf9e163051a446acaa7d"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T11:24:04.873032Z"}}