CVE-2020-26226

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/11/2020
Last modified:
03/12/2020

Description

In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded when included in a URL are already masked properly. The issue is fixed in version 17.2.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:semantic-release_project:semantic-release:*:*:*:*:*:*:*:* 17.2.3 (excluding)