Intel

AIKIDO-2024-10023

nx is vulnerable to Exposure of Sensitive System Information

Exposure of Sensitive System Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 11, 2024

82

High Risk

This Affects:

JSnx
12.3.5 - 18.1.2
Fixed in 18.1.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to exposure of sensitive system information. Sensitive keys such as NX_CLOUD_ENCRYPTION_KEY (e2e encryption token) or NX_CLOUD_ACCESS_TOKEN (access token to the cloud CI solution), when set in the environment variables, can be exposed during the bundling process.

Who does this affect?

You are affected if you are using a version of this package >=12.3.5 and = 18.1.2 and NX_CLOUD_ENCRYPTION_KEY or NX_CLOUD_ACCESS_TOKEN are set in the environment variables

Background info

nx is vulnerable to Exposure of Sensitive System Information in versions 12.3.5 - 18.1.2.

How to fix this

Upgrade the nx library to the patch version or remove NX_CLOUD_ENCRYPTION_KEY and NX_CLOUD_ACCESS_TOKEN from the environment variables.