Описание
The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can often times contain secret keys and other sensitive values. A malicious user could be on the same network as a regular user and intercept all the secret keys the user is sending. This goes against common best practice, which is to use HTTPS.
Ссылки
- Broken LinkThird Party Advisory
- Third Party Advisory
- Broken LinkThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.3.8 (включая)
cpe:2.3:a:airbrake:airbrake:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 53%
0.003
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-200
CWE-200
Связанные уязвимости
EPSS
Процентиль: 53%
0.003
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-200
CWE-200