Skip to content

Potential API key leak

Moderate
RustyBower published GHSA-63rq-p8fp-524q Apr 11, 2021

Package

sopel-weather

Affected versions

<= 1.2.3

Patched versions

1.2.4

Description

If a user is actively blackholing the location or weather APIs, or those APIs become otherwise unavailable, it is possible for the API keys to get leaked to the active IRC channel.

This is patched in v1.2.4

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs