{"id":"GHSA-j4g3-3q8x-jxqp","summary":"dbt-core's secret env vars written to package-lock.json in plaintext","details":"### Impact\n\nWhen used to pull source code from a private repository using a Personal Access Token (PAT), some versions of dbt-core write a URL with the PAT in plaintext to the `package-lock.yml` file.\n\n### Patches\n\nThe bug has been fixed in [dbt-core v1.7.3](https://github.com/dbt-labs/dbt-core/releases/tag/v1.7.3).\n\n### Mitigations\n\nRemove any git URLs with plaintext secrets from `package-lock.yml` file(s) on servers, workstations, or in source control. Rotate any tokens that have been written to version-controlled files.","modified":"2024-12-04T05:42:25.774437Z","published":"2023-12-08T15:38:37Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-315"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-12-08T15:38:37Z"},"references":[{"type":"WEB","url":"https://github.com/dbt-labs/dbt-core/security/advisories/GHSA-j4g3-3q8x-jxqp"},{"type":"WEB","url":"https://github.com/dbt-labs/dbt-core/commit/09f5bb3dcffeda7a60ad2b22c2891f237628ecd1"},{"type":"PACKAGE","url":"https://github.com/dbt-labs/dbt-core"},{"type":"WEB","url":"https://github.com/dbt-labs/dbt-core/releases/tag/v1.7.3"}],"affected":[{"package":{"name":"dbt-core","ecosystem":"PyPI","purl":"pkg:pypi/dbt-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.7.0"},{"fixed":"1.7.3"}]}],"versions":["1.7.0","1.7.1","1.7.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-j4g3-3q8x-jxqp/GHSA-j4g3-3q8x-jxqp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N"}]}