{"id":"GHSA-v7x3-7hw7-pcjg","summary":"Renovate vulnerable to leakage of temporary repository tokens into Pull Request comments","details":"### Impact\n\nTemporary repository tokens were leaked into Pull Requests comments in during certain Go Modules update failure scenarios.\n\n### Patches\n\nThe problem has been patched. Self-hosted users should upgrade to v19.38.7 or later.\n\n### Workarounds\n\nDisable Go Modules support.\n\n### References\n\nBlog post: https://renovatebot.com/blog/go-modules-vulnerability-disclosure\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [Renovate](http://github.com/renovatebot/renovate)\n","modified":"2022-08-11T13:20:10Z","published":"2019-10-21T16:02:33Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-200"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:57:15Z"},"references":[{"type":"WEB","url":"https://github.com/renovatebot/renovate/security/advisories/GHSA-v7x3-7hw7-pcjg"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-v7x3-7hw7-pcjg"},{"type":"PACKAGE","url":"https://github.com/renovatebot/renovate"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-RENOVATE-536203"}],"affected":[{"package":{"name":"renovate","ecosystem":"npm","purl":"pkg:npm/renovate"},"ranges":[{"type":"SEMVER","events":[{"introduced":"13.87.0"},{"fixed":"19.38.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-v7x3-7hw7-pcjg/GHSA-v7x3-7hw7-pcjg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}