CVE-2022-31051 affects the open-source npm package semantic-release, used for automated version management. This vulnerability allows for the accidental disclosure of secrets that contain specific characters not encoded by encodeURI, particularly in scenarios where repository push access requires injecting credentials into the URL. Rated with a CVSS score of 7.5 (High), this vulnerability has a low attack complexity and does not require user interaction or privileges, leading to a high confidentiality impact. The FAUCET Risk Score is 52/100, indicating a moderate risk. Currently, there is no evidence of active exploitation, and no exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, which is typical for the majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.0.4, < 19.0.3CPE matchmatch criteria | cpe:2.3:a:semantic-release_project:semantic-release:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.