npm package
semantic-release
pkg:npm/semantic-release
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-31051 | — | >= 17.0.4, < 19.0.3 | 19.0.3 | Jun 9, 2022 | semantic-release is an open source npm package for automated version management and package publishing. In affected versions secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that are excluded from uri encoding by ` | ||
| CVE-2020-26226 | — | < 17.2.3 | 17.2.3 | Nov 18, 2020 | In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded w |
- CVE-2022-31051Jun 9, 2022affected >= 17.0.4, < 19.0.3fixed 19.0.3
semantic-release is an open source npm package for automated version management and package publishing. In affected versions secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that are excluded from uri encoding by `
- CVE-2020-26226Nov 18, 2020affected < 17.2.3fixed 17.2.3
In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded w