In EasyBuild before version 4.1.2, the GitHub Personal Access Token (PAT) used by EasyBuild for the GitHub integration features (like `--new-pr`, `--fro,-pr`, etc.) is shown in plain text in EasyBuild debug log files. This issue is fixed in EasyBuild v4.1.2, and in the `master`+ `develop` branches of the `easybuild-framework` repository.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-0075 In EasyBuild before version 4.1.2, the GitHub Personal Access Token (PAT) used by EasyBuild for the GitHub integration features (like `--new-pr`, `--fro,-pr`, etc.) is shown in plain text in EasyBuild debug log files. This issue is fixed in EasyBuild v4.1.2, and in the `master`+ `develop` branches of the `easybuild-framework` repository.
Github GHSA Github GHSA GHSA-2wx6-wc87-rmjm GitHub personal access token leaking into temporary EasyBuild (debug) logs
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-04T08:22:09.105Z

Reserved: 2020-01-02T00:00:00

Link: CVE-2020-5262

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-03-19T17:15:13.000

Modified: 2024-11-21T05:33:47.540

Link: CVE-2020-5262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses