Vulnerabilities > CVE-2020-5262 - Insecure Storage of Sensitive Information vulnerability in Easybuild Project Easybuild

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
easybuild-project
CWE-922

Summary

In EasyBuild before version 4.1.2, the GitHub Personal Access Token (PAT) used by EasyBuild for the GitHub integration features (like `--new-pr`, `--fro,-pr`, etc.) is shown in plain text in EasyBuild debug log files. This issue is fixed in EasyBuild v4.1.2, and in the `master`+ `develop` branches of the `easybuild-framework` repository.

Vulnerable Configurations

Part Description Count
Application
Easybuild_Project
84

Common Weakness Enumeration (CWE)