Vulnerability Description
Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction. Anyone with access to saved logs could obtain the bot credentials. Fixed in 23.25.1; Azure DevOps users should revoke and regenerate credentials if logs may have been exposed.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/renovatebot/renovate/security/advisories/GHSA-36rh-ggpr-j3gj
- https://www.vulncheck.com/advisories/renovate-before-token-leakage-via-logs
FAQ
What is CVE-2020-37267?
CVE-2020-37267 is a vulnerability with a CVSS score of 7.5 (HIGH). Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is ...
How severe is CVE-2020-37267?
CVE-2020-37267 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-37267?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.