Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fc4h-xcf3-qj5f

Опубликовано: 25 окт. 2022
Источник: github
Github: Прошло ревью

Описание

matrix-sdk 0.6.0 logs access tokens

When sending Matrix requests using an affected version of matrix-sdk in an application that writes logs using tracing-subscriber (in a way that includes fields of tracing spans such as tracing_subscribers default text output from the fmt module), these logs will contain the user's access token.

Пакеты

Наименование

matrix-sdk

rust
Затронутые версииВерсия исправления

>= 0.6.0, < 0.6.2

0.6.2