Sensitive Information leak via Script File in TinaCMS
CVE-2023-25164

8.6HIGH

Key Information:

Vendor

Tinacms

Status
Vendor
CVE Published:
8 February 2023

What is CVE-2023-25164?

TinaCMS, a Git-backed headless content management system, has a vulnerability where sensitive values stored in the process.env variable are inadvertently exposed in plaintext within the index.js file. This issue impacts versions of the TinaCMS CLI ranging from 1.0.0 to prior to 1.0.9, specifically affecting websites that store sensitive credentials, such as API keys, as environment variables. Affected users are strongly advised to rotate any exposed sensitive keys and update to the patched version @tinacms/[email protected] to mitigate any potential risks associated with this vulnerability. No known workarounds exist, making immediate action essential for securing your applications.

Affected Version(s)

tinacms >= 1.0.0, < 1.0.9

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.