CVE-2020-26226
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/11/2020
Last modified:
03/12/2020
Description
In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded when included in a URL are already masked properly. The issue is fixed in version 17.2.3.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:semantic-release_project:semantic-release:*:*:*:*:*:*:*:* | 17.2.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



