HIGH7.5
GHSA-4qrm-9h4r-v2fx
Tina search token leak via lock file in TinaCMS
Quick fix
GHSA-4qrm-9h4r-v2fx — @tinacms/cli: upgrade to the fixed version with the command below.
npm install @tinacms/cli@1.6.2Details
### Impact Tina search token leaked via lock file (tina-lock.json) in TinaCMS. Sites building with @tinacms/cli < 1.6.2 that use a search token are impacted.
If your Tina-enabled website has search setup, you should rotate that key immediately.
### Patches This issue has been patched in @tinacms/cli@1.6.2
### Workarounds Upgrading, and rotating search token is required for the proper fix.
### References https://github.com/tinacms/tinacms/pull/4758
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/tinacms/tinacms/security/advisories/GHSA-4qrm-9h4r-v2fx[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-45391[ADVISORY]
- https://github.com/tinacms/tinacms/pull/4758[WEB]
- https://github.com/tinacms/tinacms/commit/110f1ceea4574d636a64526648f7c8bf6539b26a[WEB]
- https://github.com/tinacms/tinacms[PACKAGE]