A potential logging of the firestore key via logging within nodejs-firestore exists - Developers who were logging objects through this._settings would be logging the firestore key as well potentially exposing it to anyone with logs read access. We recommend upgrading to version 6.1.0 to avoid this issue
{ "nvd_published_at": "2023-12-04T13:15:07Z", "github_reviewed_at": "2023-12-04T23:13:52Z", "github_reviewed": true, "severity": "MODERATE", "cwe_ids": [ "CWE-532", "CWE-922" ] }