eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is exposed in .env. A valid Supabase URI with embedded username and password will allow an attacker complete unauthorized access and control over database and user data. This could lead to data exfiltration, modification or deletion.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 Aug 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is exposed in .env. A valid Supabase URI with embedded username and password will allow an attacker complete unauthorized access and control over database and user data. This could lead to data exfiltration, modification or deletion. | |
| Title | eslint-ban-moment exposed a sensitive Supabase URI in .env (Credential leak) | |
| Weaknesses | CWE-260 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-21T16:14:29.391Z
Updated: 2025-08-21T17:31:58.060Z
Reserved: 2025-08-19T15:16:22.916Z
Link: CVE-2025-57754
Updated: 2025-08-21T17:23:56.292Z
Status : Awaiting Analysis
Published: 2025-08-21T17:15:31.420
Modified: 2025-08-22T18:08:51.663
Link: CVE-2025-57754
No data.