Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35926
HistoryJun 10, 2022 - 5:15 a.m.

Information Disclosure

2022-06-1005:15:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.002 Low

EPSS

Percentile

60.0%

semantic-release is vulnerable to information disclosure. The vulnerability exists when the repository URL contains characters that are excluded from URI encoding by encodeURI, allowing an attacker to get access to sensitive information through the logs due to the lack of credential masking used in index.js

0.002 Low

EPSS

Percentile

60.0%