Описание
Logging Redactor is a Python library designed to redact sensitive data in logs based on regex patterns and / or dictionary keys. Prior to version 0.0.6, non-string types are converted into string types, leading to type errors in %d conversions. The problem has been patched in version 0.0.6. No known workarounds are available.
Ссылки
- ExploitIssue Tracking
- Release Notes
- Vendor Advisory
- ExploitIssue Tracking
Уязвимые конфигурации
Конфигурация 1Версия до 0.0.6 (исключая)
cpe:2.3:a:armurox:logging_redactor:*:*:*:*:*:python:*:*
EPSS
Процентиль: 8%
0.00029
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-704
Связанные уязвимости
github
около 1 месяца назад
loggingredactor converts non-string types to string types in logs
EPSS
Процентиль: 8%
0.00029
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-704