{"id":"GHSA-36rh-ggpr-j3gj","summary":"Renovate vulnerable to Azure DevOps token leakage in logs","details":"### Impact\n\nApplies to Azure DevOps users only. The bot's token may be exposed in server or pipeline logs due to the `http.extraheader=AUTHORIZATION` parameter being logged without redaction. It is recommended that Azure DevOps users revoke their existing bot credentials and generate new ones after upgrading if there's a potential that logs have been saved to a location that others can view.\n\n### Patches\n\nFixed in \n\n### Workarounds\n\nDo not share Renovate logs with anyone who cannot be trusted with access to the token.\n","modified":"2022-08-11T13:19:15Z","published":"2020-09-14T16:38:40Z","database_specific":{"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-09-14T16:38:10Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-36rh-ggpr-j3gj"},{"type":"PACKAGE","url":"https://github.com/renovatebot/renovate"}],"affected":[{"package":{"name":"renovate","ecosystem":"npm","purl":"pkg:npm/renovate"},"ranges":[{"type":"SEMVER","events":[{"introduced":"19.180.0"},{"fixed":"23.25.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-36rh-ggpr-j3gj/GHSA-36rh-ggpr-j3gj.json"}}],"schema_version":"1.9.0"}