VDB
Sign up
LOW3.2

GHSA-j4g3-3q8x-jxqp

dbt-core's secret env vars written to package-lock.json in plaintext

Quick fix

GHSA-j4g3-3q8x-jxqp — dbt-core: upgrade to the fixed version with the command below.

pip install --upgrade 'dbt-core>=1.7.3'

Details

### Impact

When used to pull source code from a private repository using a Personal Access Token (PAT), some versions of dbt-core write a URL with the PAT in plaintext to the `package-lock.yml` file.

### Patches

The bug has been fixed in [dbt-core v1.7.3](https://github.com/dbt-labs/dbt-core/releases/tag/v1.7.3).

### Mitigations

Remove any git URLs with plaintext secrets from `package-lock.yml` file(s) on servers, workstations, or in source control. Rotate any tokens that have been written to version-controlled files.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/dbt-core
Introduced in: 1.7.0Fixed in: 1.7.3
Fixpip install --upgrade 'dbt-core>=1.7.3'

References