s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2023-2138

📛 CVE Title

Use of Hard-coded Credentials in nuxtlabs/github-module

Description

Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.

Overview

State
PUBLISHED
Assigner (CNA)
@huntrdev
CVSS severity
CRITICAL
CVSS score
CVSS 10.0 / 10 10.0 10.0 / 10
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Effective score
10.0 / 10 CRITICAL source: CNA overview
CWE(s)
CWE-798
Reserved
2023-04-18
Published
2023-04-18 02:00 UTC
Last updated
2025-02-05 21:27 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/2xxx/CVE-2023-2138.json
Linked Threat
CVE-2023-2138 — Use of Hard-coded Credentials in nuxtlabs/github-module

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2023-1292
Assigner
@huntrdev
Published
Apr 18, 2023, 12:00:00 AM
Updated
Feb 5, 2025, 8:27:31 PM
EUVD base score (CVSS 3.0)
10.0 / 10
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EUVD-reported EPSS
0.3600
Vendors
nuxtlabs
Products
nuxtlabs/github-module (unspecified <1.6.2)
Aliases
GHSA-fp2w-g92g-fgq4

ENISA description: Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.

EUVD references (2)

Affected products (1)

VendorProductVersionsPlatforms
nuxtlabs nuxtlabs/github-module unspecified (affected)

Vendor references (2)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

Remediations (17)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:www.3cx.com

    3CX has released a security hotfix relating to a third party component. Check if you're affected and apply the latest update immediately.

    2026-06-11 17:16 UTC
  • web:www.oracle.com

    Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.

    2026-06-11 17:16 UTC
  • web:techdocs.broadcom.com

    Patch Category Security Patch Severity Critical Host Reboot Required Yes Virtual Machine Migration or Shutdown Required Yes Affected Hardware N/A Affected Software N/A Affected VIBs Included VMware_bootbank_esxio-update_8..3-.60.24585383 VMware_bootbank_loadesxio_8..3-.60.24585383 PRs Fixed N/A CVE numbers N/A Due to their dependency on the ...

    2026-06-11 17:16 UTC
  • web:www.reuters.com

    The U.S. cyber defense agency said on Wednesday that government officials now have three days to deal with the most ‌serious categories of digital vulnerabilities in their networks, a compressed ...

    2026-06-11 17:16 UTC
  • web:www.manageengine.com

    Unfold what this Patch Tuesday has in store for you Patch Tuesday, the unofficial term for Microsoft's scheduled security fix release on every second Tuesday of a month, has been a constant topic of discussion ever since its inception. Upcoming Webinar June 11,2026 11:30 EDT & 6:30 a.m. GMT Agenda of the Free Patch Tuesday webinar A complete breakdown of all the latest Patch Tuesday updates ...

    2026-06-11 17:16 UTC
  • web:www.veeam.com

    When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information.

    2026-06-11 17:16 UTC
  • web:access.redhat.com

    Learn about our open source products, services, and company. You are here

    2026-06-11 17:16 UTC
  • web:www.ninjaone.com

    Catalog of Microsoft KB updates with insights on performance & user sentiment. Find out what's working, what's not, & make informed decisions.

    2026-05-22 06:20 UTC
  • web:www.oracle.com

    This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.

    2026-05-22 06:20 UTC
  • web:www.securityweek.com

    Microsoft has announced mitigations for CVE -2026-45585, a BitLocker bypass triggered via FsTx in Windows Recovery.

    2026-05-22 06:20 UTC
  • web:zecurit.com

    Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .

    2026-05-22 06:20 UTC
  • web:cybersecuritynews.com

    Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.

    2026-05-22 06:20 UTC
  • web:nvd.nist.gov

    Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

    2026-05-22 06:20 UTC
  • web:petervanderwoude.nl

    This week is all about the latest changes in updating Windows 11 devices. That change is the introduction of hotpatch updates for Windows 11 Enterprise. Hotpatching helps organizations with keeping Windows secure, while minimizing the disruptions for the user. A significant step in keeping Windows more secure and productive. Hotpatching removes the requirement for Windows…

    2026-05-22 06:20 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-05-22 06:20 UTC
  • web:windowsreport.com

    It's that time of the month again: Microsoft has rolled out its Patch Tuesday updates for Windows 11 versions 23H2, 22H2, and 21H2. Windows 11 23H2 and 22H2 users will see their systems updated through KB5041585, while those on 21H2 will receive KB5041592. Post-update, your build versions will be 22621.4037, 22631.4037, and 22000.3147, respectively. The updates include quality improvements ...

    2026-05-22 06:20 UTC
  • web:www.cve.org

    At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures

    2026-05-22 06:20 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2023-2138.json.

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T06:12:20.544Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://huntr.dev/bounties/65096ef9-eafc-49da-b49a-5b88c0203ca6"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://github.com/nuxtlabs/github-module/commit/5490c43f729eee60f07920bf88c0aabdc1398b6e"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2023-2138",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-02-05T20:27:24.907372Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-02-05T20:27:31.707Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "nuxtlabs/github-module",
          "vendor": "nuxtlabs",
          "versions": [
            {
              "lessThan": "1.6.2",
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2."
        }
      ],
      "metrics": [
        {
          "cvssV3_0": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 10,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-798",
              "description": "CWE-798 Use of Hard-coded Credentials",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2023-04-18T00:00:00.000Z",
        "orgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
        "shortName": "@huntrdev"
      },
      "references": [
        {
          "url": "https://huntr.dev/bounties/65096ef9-eafc-49da-b49a-5b88c0203ca6"
        },
        {
          "url": "https://github.com/nuxtlabs/github-module/commit/5490c43f729eee60f07920bf88c0aabdc1398b6e"
        }
      ],
      "source": {
        "advisory": "65096ef9-eafc-49da-b49a-5b88c0203ca6",
        "discovery": "EXTERNAL"
      },
      "title": "Use of Hard-coded Credentials in nuxtlabs/github-module"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "c09c270a-b464-47c1-9133-acb35b22c19a",
    "assignerShortName": "@huntrdev",
    "cveId": "CVE-2023-2138",
    "datePublished": "2023-04-18T00:00:00.000Z",
    "dateReserved": "2023-04-18T00:00:00.000Z",
    "dateUpdated": "2025-02-05T20:27:31.707Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}