github.com/buildkite/agent/v3 is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere
20
Low Risk
Affected versions of this package are vulnerable to Information Disclosure, where a refactor introduced an unhandled error in the secrets rejection function, allowing pipelines with cleartext secrets, such as passwords or API keys, to be uploaded even when the --reject-secrets flag was enabled. An attacker could exploit this vulnerability by deliberately submitting malicious pipeline configurations that contain exposed secrets, thereby bypassing intended safeguards and potentially leading to unauthorized access or data exposure.
You are affected if you are using a version that falls within the vulnerable range.
github.com/buildkite/agent/v3 is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 3.0.0 - 3.112.0.
Upgrade the github.com/buildkite/agent/v3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant