Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTYzcnEtcDhmcC01MjRx
Potential API key leak
If a user is actively blackholing the location or weather APIs, or those APIs become otherwise unavailable, it is possible for the API keys to get leaked to the active IRC channel.
This is patched in v1.2.4
Permalink: https://github.com/advisories/GHSA-63rq-p8fp-524qJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTYzcnEtcDhmcC01MjRx
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 3 years ago
Updated: over 1 year ago
Identifiers: GHSA-63rq-p8fp-524q
References:
- https://github.com/sopel-irc/sopel-weather/security/advisories/GHSA-63rq-p8fp-524q
- https://github.com/advisories/GHSA-63rq-p8fp-524q
Blast Radius: 0.0
Affected Packages
pypi:sopel-modules.weather
Dependent packages: 0Dependent repositories: 1
Downloads: 107 last month
Affected Version Ranges: < 1.2.4
Fixed in: 1.2.4
All affected versions: 0.0.1, 0.0.2, 0.0.3, 0.0.4, 0.0.5, 0.0.6, 0.0.7, 1.0.0, 1.0.1, 1.0.2, 1.1.0, 1.2.0, 1.2.1, 1.2.2
All unaffected versions: 1.2.4, 1.2.5, 1.3.0, 1.3.1, 1.4.0, 1.5.0, 1.5.1, 1.6.0, 1.6.1