Tina search token leak via lock file in TinaCMS
Description
Published to the GitHub Advisory Database
Sep 3, 2024
Reviewed
Sep 3, 2024
Published by the National Vulnerability Database
Sep 3, 2024
Last updated
Sep 12, 2024
Impact
Tina search token leaked via lock file (tina-lock.json) in TinaCMS. Sites building with @tinacms/cli < 1.6.2 that use a search token are impacted.
If your Tina-enabled website has search setup, you should rotate that key immediately.
Patches
This issue has been patched in @tinacms/[email protected]
Workarounds
Upgrading, and rotating search token is required for the proper fix.
References
tinacms/tinacms#4758
References