Intel

AIKIDO-2024-10546

docusaurus-theme-openapi-docs is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 19, 2024

48

Medium Risk

This Affects:

JSdocusaurus-theme-openapi-docs
0.0.13 - 4.3.0
Fixed in 4.3.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package expose credentials in generated code snippets, potentially leading to unauthorized access or data breaches if the snippets are shared or accessed by unauthorized parties.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

docusaurus-theme-openapi-docs is vulnerable to Information Disclosure in versions 0.0.13 - 4.3.0.

How to fix this

Upgrade the docusaurus-theme-openapi-docs library to the patch version.