CVE-2023-2138: Use of Hard-coded Credentials in nuxtlabs/github-module
https://nuxt.com had a hardcoded GitHub token in the source code of the page. This token had access to multiple repositories under nuxt, nuxtlabs and nuxt-themes GitHub organizations. A patch in version 1.6.2 fixed the issue.
Other sources
Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2138?
CVE-2023-2138 is classified as a high severity vulnerability due to the exposure of hardcoded credentials.
How do I fix CVE-2023-2138?
To resolve CVE-2023-2138, update the affected package @nuxtlabs/github-module to version 1.6.2 or later.
What software is affected by CVE-2023-2138?
CVE-2023-2138 affects the @nuxtlabs/github-module package and Nuxt.js versions prior to 1.6.2.
What was exposed in CVE-2023-2138?
CVE-2023-2138 exposed a hardcoded GitHub token that provided access to various repositories on GitHub.
Is there a patch available for CVE-2023-2138?
Yes, a patch to fix CVE-2023-2138 was released in version 1.6.2 of the affected package.