CVE-2020-37267
renovatebot renovate
Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction. Anyone with access to saved logs could obtain the bot credentials. Fixed in 23.25.1; Azure DevOps users should revoke and regenerate credentials if logs may have been exposed.
- CVSS
- 8.7
- EPSS
- 0.31% 23.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.19