What is CVE-2020-37267?
CVE-2020-37267 is a vulnerability in Renovate versions >=19.180.0 and <23.25.1 when used with Azure DevOps, where the bot's authorization token is exposed in server or pipeline logs due to unredacted logging of the git http.extraheader parameter. This allows anyone with log access to obtain bot credentials. Users must upgrade to Renovate version 23.25.1 or later to fix the issue.
Azərbaycanca: CVE-2020-37267, Azure DevOps ilə istifadə edilən Renovate bot-un 19.180.0-dən 23.25.1-ə qədər versiyalarında authorization token-in server və pipeline log-larında redaktə olunmadan qeydə alınmasına səbəb olan boşluqdur. Bu log-lara girişi olan hər kəs bot etimadnamələrini əldə edə bilər. İstifadəçilər dərhal bot proqramını 23.25.1 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which product users are affected by the CVE-2020-37267 vulnerability?
This vulnerability affects versions of the Renovate bot from 19.180.0 to prior to 23.25.1 when used with Azure DevOps.
To which version should Renovate be upgraded to fix CVE-2020-37267?
Users must immediately upgrade the Renovate bot to version 23.25.1 or later to resolve the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.