Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTYzcnEtcDhmcC01MjRx

Potential API key leak

If a user is actively blackholing the location or weather APIs, or those APIs become otherwise unavailable, it is possible for the API keys to get leaked to the active IRC channel.

This is patched in v1.2.4

Permalink: https://github.com/advisories/GHSA-63rq-p8fp-524q
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTYzcnEtcDhmcC01MjRx
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 3 years ago
Updated: over 1 year ago


Identifiers: GHSA-63rq-p8fp-524q
References: Repository: https://github.com/sopel-irc/sopel-weather
Blast Radius: 0.0

Affected Packages

pypi:sopel-modules.weather
Dependent packages: 0
Dependent repositories: 1
Downloads: 107 last month
Affected Version Ranges: < 1.2.4
Fixed in: 1.2.4
All affected versions: 0.0.1, 0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.7, 1.0.0, 1.0.1, 1.0.2, 1.1.0, 1.2.0, 1.2.1, 1.2.2
All unaffected versions: 1.2.4, 1.2.5, 1.3.0, 1.3.1, 1.4.0, 1.5.0, 1.5.1, 1.6.0, 1.6.1