Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2712 | Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search token may be vulnerable to the search token being leaked via lock file (tina-lock.json). Administrators of Tina-enabled websites with search setup should rotate their key immediately. This issue has been patched in @tinacms/cli version 1.6.2. Upgrading and rotating the search token is required for the proper fix. |
Github GHSA |
GHSA-4qrm-9h4r-v2fx | Tina search token leak via lock file in TinaCMS |
Fri, 13 Mar 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ssw
Ssw tinacms\/cli |
|
| CPEs | cpe:2.3:a:ssw:tinacms\/cli:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Tina
Tina tina |
Ssw
Ssw tinacms\/cli |
Thu, 12 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tina
Tina tina |
|
| Weaknesses | CWE-312 | |
| CPEs | cpe:2.3:a:tina:tina:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tina
Tina tina |
Tue, 03 Sep 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Sep 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search token may be vulnerable to the search token being leaked via lock file (tina-lock.json). Administrators of Tina-enabled websites with search setup should rotate their key immediately. This issue has been patched in @tinacms/cli version 1.6.2. Upgrading and rotating the search token is required for the proper fix. | |
| Title | Tina search token leak via lock file in TinaCMS | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-03T20:23:59.611Z
Reserved: 2024-08-28T20:21:32.801Z
Link: CVE-2024-45391
Updated: 2024-09-03T20:23:56.008Z
Status : Analyzed
Published: 2024-09-03T20:15:08.627
Modified: 2026-03-13T19:37:28.693
Link: CVE-2024-45391
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA