Description
aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled and published to npm the user (that performed a aegir-release) GitHub token.
Remediation
References
https://nodesecurity.io/advisories/546
Related Vulnerabilities
CVE-2020-2223 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-2258 Vulnerability in maven package org.jenkins-ci.plugins:cloudbees-jenkins-advisor
CVE-2021-3189 Vulnerability in npm package slashify
CVE-2017-8046 Vulnerability in maven package org.springframework.boot:spring-boot-starter-data-rest
CVE-2022-36917 Vulnerability in maven package org.jenkins-ci.plugins:google-cloud-backup