Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-pc2q-jcxq-rjrr: Sensitive Information leak via Script File in TinaCMS

Impact

Sensitive Information leaked via script File in TinaCMS. Sites building with @tinacms/cli >= 1.0.0 && < 1.0.9 that store sensitive values in process.env var are impacted. If you’re on a version prior to 1.0.0 this vulnerability does not affect you.

If your Tina-enabled website has sensitive credentials stored as environment variables (eg. Algolia API keys) you should rotate those keys immediately.

Patches

This issue has been patched in @tinacms/cli@1.0.9

Workarounds

Upgrading, and rotating secure & exposed keys is required for the proper fix.

References

https://github.com/tinacms/tinacms/pull/3584

ghsa
#vulnerability#web#git

Impact

Sensitive Information leaked via script File in TinaCMS. Sites building with @tinacms/cli >= 1.0.0 && < 1.0.9 that store sensitive values in process.env var are impacted. If you’re on a version prior to 1.0.0 this vulnerability does not affect you.

If your Tina-enabled website has sensitive credentials stored as environment variables (eg. Algolia API keys) you should rotate those keys immediately.

Patches

This issue has been patched in @tinacms/cli@1.0.9

Workarounds

Upgrading, and rotating secure & exposed keys is required for the proper fix.

References

tinacms/tinacms#3584

References

  • GHSA-pc2q-jcxq-rjrr

ghsa: Latest News

GHSA-8qq5-rm4j-mr97: node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization