Renovate vulnerable to Azure DevOps token leakage in logs
GHSA-36rh-ggpr-j3gj
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
Applies to Azure DevOps users only. The bot's token may be exposed in server or pipeline logs due to the http.extraheader=AUTHORIZATION parameter being logged without redaction. It is recommended that Azure DevOps users revoke their existing bot credentials and generate new ones after upgrading if there's a potential that logs have been saved to a location that others can view.
Patches
Fixed in
Workarounds
Do not share Renovate logs with anyone who cannot be trusted with access to the token.
Ready to move
Start Securing
Free, no credit card | First findings in minutes