CVE-2024-45391: Tina search token leak via lock file in TinaCMS

Published Sep 3, 2024
·
Updated

Impact Tina search token leaked via lock file (tina-lock.json) in TinaCMS. Sites building with @tinacms/cli < 1.6.2 that use a search token are impacted.

If your Tina-enabled website has search setup, you should rotate that key immediately.

Patches This issue has been patched in @tinacms/cli@1.6.2

Workarounds Upgrading, and rotating search token is required for the proper fix.

References https://github.com/tinacms/tinacms/pull/4758

Other sources

Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search token may be vulnerable to the search token being leaked via lock file (tina-lock.json). Administrators of Tina-enabled websites with search setup should rotate their key immediately. This issue has been patched in @tinacms/cli version 1.6.2. Upgrading and rotating the search token is required for the proper fix.

MITRE

Affected Software

3 affected componentsFixes available
npm/@tinacms/cli<1.6.2
1.6.2
Tina Tina<1.6.2
ssw Tinacms\/cli Node.js<1.6.2

Event History

Sep 3, 2024
Advisory Published
via GitHub·07:41 PM
CVE Published
via MITRE·07:43 PM
Data Sourced
via MITRE·07:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-45391?

CVE-2024-45391 has been classified as a significant vulnerability due to the potential leakage of search tokens.

2

How do I fix CVE-2024-45391?

To fix CVE-2024-45391, upgrade @tinacms/cli to version 1.6.2 or higher immediately.

3

What impact does CVE-2024-45391 have on my website?

CVE-2024-45391 can lead to exposure of sensitive search tokens, compromising the security of your TinaCMS-enabled site.

4

Which versions of software are affected by CVE-2024-45391?

CVE-2024-45391 affects all versions of @tinacms/cli prior to 1.6.2.

5

What should I do if I have been impacted by CVE-2024-45391?

If impacted by CVE-2024-45391, it is essential to rotate the leaked search token as soon as possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203