Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-99j7-mhfh-w84p

Опубликовано: 20 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Slack Morphism for Rust before 0.41.0 can leak Slack OAuth client information in application debug logs

Impact

Potential/accidental leaking of Slack OAuth client information in application debug logs.

Patches

More strict and secure debug formatting was introduced in v0.41 for OAuth secret types to avoid the possibility of printing sensitive information in application logs.

Workarounds

Don't print/output in logs request and responses for OAuth and client configurations.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

slack-morphism

rust
Затронутые версииВерсия исправления

< 0.41.0

0.41.0

EPSS

Процентиль: 60%
0.00391
Низкий

7.5 High

CVSS3

Дефекты

CWE-1258
CWE-200
CWE-212

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

Slack Morphism is an async client library for Rust. Prior to 0.41.0, it was possible for Slack OAuth client information to leak in application debug logs. Stricter and more secure debug formatting was introduced in v0.41.0 for OAuth secret types to reduce the possibility of printing sensitive information in application logs. As a workaround, do not print/output requests and responses for OAuth and client configurations in logs.

EPSS

Процентиль: 60%
0.00391
Низкий

7.5 High

CVSS3

Дефекты

CWE-1258
CWE-200
CWE-212