Token Exposure in Renovate Tool Used for Dependency Management
CVE-2019-25766
8.7HIGH
What is CVE-2019-25766?
Versions of the Renovate tool between 13.87.0 and 19.38.6 are susceptible to a vulnerability that may lead to the leakage of temporary repository tokens. This occurs in specific scenarios following failed updates of Go Modules, where tokens can appear in pull request comments, exposing sensitive credentials to anyone with access to the comments. The issue has been addressed in version 19.38.7, and users are strongly advised to upgrade to this version to mitigate the risk of token exposure.
Affected Version(s)
renovate 13.87.0 < 19.38.7
renovate 19.38.7
