{"id":"GHSA-j4g3-3q8x-jxqp","aliases":[],"url":"https://o3.security/vulnerability/GHSA-j4g3-3q8x-jxqp","summary":"dbt-core's secret env vars written to package-lock.json in plaintext","details":"### Impact\n\nWhen used to pull source code from a private repository using a Personal Access Token (PAT), some versions of dbt-core write a URL with the PAT in plaintext to the `package-lock.yml` file.\n\n### Patches\n\nThe bug has been fixed in [dbt-core v1.7.3](https://github.com/dbt-labs/dbt-core/releases/tag/v1.7.3).\n\n### Mitigations\n\nRemove any git URLs with plaintext secrets from `package-lock.yml` file(s) on servers, workstations, or in source control. Rotate any tokens that have been written to version-controlled files.","published":"2023-12-08T15:38:37Z","modified":"2024-12-04T05:42:25.774437Z","cvss":{"score":3.2,"severity":"LOW","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"dbt-core","fixedVersion":"1.7.3"}],"fix":{"url":"https://github.com/dbt-labs/dbt-core/commit/09f5bb3dcffeda7a60ad2b22c2891f237628ecd1","label":"dbt-labs/dbt-core@09f5bb3"},"references":[{"type":"WEB","url":"https://github.com/dbt-labs/dbt-core/security/advisories/GHSA-j4g3-3q8x-jxqp"},{"type":"WEB","url":"https://github.com/dbt-labs/dbt-core/commit/09f5bb3dcffeda7a60ad2b22c2891f237628ecd1"},{"type":"PACKAGE","url":"https://github.com/dbt-labs/dbt-core"},{"type":"WEB","url":"https://github.com/dbt-labs/dbt-core/releases/tag/v1.7.3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:42:25.774437Z"}}