Loading HuntDB...

GHSA-rrj3-qmh8-72pf

GitHub Security Advisory

grunt-gh-pages before 0.10.0 may allow unencrypted GitHub credentials to be written to a log file

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Versions of `grunt-gh-pages` prior to 0.10.0 are affected by a vulnerability which may cause unencrypted GitHub credentials to be written to a log file in certain circumstances.

In the `grunt-gh-pages` deployment scenario where authentication is performed by injecting a GitHub token directly into the auth portion of the URL, `grunt-gh-pages` will write the token to a log file, unencrypted.

## Recommendation

Update to version 0.10.0 or later.

Affected Packages

npm grunt-gh-pages
Affected versions: 0 (fixed in 0.10.0)

Related CVEs

Key Information

GHSA ID
GHSA-rrj3-qmh8-72pf
Published
February 18, 2019 11:39 PM
Last Modified
August 3, 2022 11:53 PM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
grunt-gh-pages
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 4, 2025 6:20 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.