漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Sensitive Information leak via Script File in TinaCMS
Vulnerability Description
Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 which store sensitive values in the process.env variable are impacted. These values will be added in plaintext to the index.js file. If you're on a version prior to 1.0.0 this vulnerability does not affect you. If you are affected and your Tina-enabled website has sensitive credentials stored as environment variables (eg. Algolia API keys) you should rotate those keys immediately. This issue has been patched in @tinacms/cli@1.0.9. Users are advised to upgrade. There are no known workarounds for this issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
通过日志文件的信息暴露
Vulnerability Title
TinaCMS 日志信息泄露漏洞
Vulnerability Description
TinaCMS是一个用于 Markdown、MDX 和 JSON 的开源无头 CMS。 TinaCMS 1.0.9之前版本存在日志信息泄露漏洞,该漏洞源于在process.env变量中存储的敏感值以明文形式添加在index.js文件中。
CVSS Information
N/A
Vulnerability Type
N/A