Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39191
HistoryFeb 10, 2023 - 2:58 a.m.

Information Disclosure

2023-02-1002:58:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
information disclosure
environment variables
index.js
read only token
sensitive information
security vulnerability

EPSS

0.002

Percentile

53.0%

@tinacms/app is vulnerable to Information Disclosure. The vulnerability exists because the viteBuild function in index.ts exposes environment variables to index.js, allowing an attacker to use a read only token to gain access to sensitive information.

EPSS

0.002

Percentile

53.0%