{"id":"GHSA-v7x3-7hw7-pcjg","aliases":[],"url":"https://o3.security/vulnerability/GHSA-v7x3-7hw7-pcjg","summary":"Renovate vulnerable to leakage of temporary repository tokens into Pull Request comments","details":"### Impact\n\nTemporary repository tokens were leaked into Pull Requests comments in during certain Go Modules update failure scenarios.\n\n### Patches\n\nThe problem has been patched. Self-hosted users should upgrade to v19.38.7 or later.\n\n### Workarounds\n\nDisable Go Modules support.\n\n### References\n\nBlog post: https://renovatebot.com/blog/go-modules-vulnerability-disclosure\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [Renovate](http://github.com/renovatebot/renovate)\n","published":"2019-10-21T16:02:33Z","modified":"2022-08-11T13:20:10Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"renovate","fixedVersion":"19.38.7"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-v7x3-7hw7-pcjg"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-v7x3-7hw7-pcjg"},{"type":"PACKAGE","url":"https://github.com/renovatebot/renovate"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-RENOVATE-536203"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2022-08-11T13:20:10Z"}}