{"id":"GHSA-36rh-ggpr-j3gj","aliases":[],"url":"https://o3.security/vulnerability/GHSA-36rh-ggpr-j3gj","summary":"Renovate vulnerable to Azure DevOps token leakage in logs","details":"### Impact\n\nApplies to Azure DevOps users only. The bot's token may be exposed in server or pipeline logs due to the `http.extraheader=AUTHORIZATION` parameter being logged without redaction. It is recommended that Azure DevOps users revoke their existing bot credentials and generate new ones after upgrading if there's a potential that logs have been saved to a location that others can view.\n\n### Patches\n\nFixed in \n\n### Workarounds\n\nDo not share Renovate logs with anyone who cannot be trusted with access to the token.\n","published":"2020-09-14T16:38:40Z","modified":"2022-08-11T13:19:15Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"renovate","fixedVersion":"23.25.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-36rh-ggpr-j3gj"},{"type":"PACKAGE","url":"https://github.com/renovatebot/renovate"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2022-08-11T13:19:15Z"}}