Description
aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled and published to npm the user (that performed a aegir-release) GitHub token.
Affected products
- HackerOne / aegir node module>=12.0.0 <= 12.0.7 – >=12.0.0 <= 12.0.7
References
- VENDOR_ADVISORYhttps://nodesecurity.io/advisories/546