Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1oNHE4LTk2cDYtamNncs4AAwbW

ghinstallation returns app JWT in error responses

Impact

In ghinstallation v1, when the request to refresh an installation token failed, the HTTP request and response would be returned for debugging.

https://github.com/bradleyfalzon/ghinstallation/blob/24e56b3fb7669f209134a01eff731d7e2ef72a5c/transport.go#L172-L174

The request contained the bearer JWT for the App, and was returned back to clients. This token is short lived (10 minute maximum).

Patches

References

Are there any links users can visit to find out more?

For more information

If you have any questions or comments about this advisory:

Permalink: https://github.com/advisories/GHSA-h4q8-96p6-jcgr
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oNHE4LTk2cDYtamNncs4AAwbW
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 1 year ago
Updated: 8 months ago


CVSS Score: 5.0
CVSS vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:L

Identifiers: GHSA-h4q8-96p6-jcgr, CVE-2022-39304
References: Repository: https://github.com/bradleyfalzon/ghinstallation
Blast Radius: 12.8

Affected Packages

go:github.com/bradleyfalzon/ghinstallation
Dependent packages: 266
Dependent repositories: 360
Downloads:
Affected Version Ranges: < 2.0.0
Fixed in: 2.0.0
All affected versions: 0.1.0, 0.1.1, 0.1.2, 0.1.3, 1.0.0, 1.1.0, 1.1.1
All unaffected versions: