GHSA-4mjx-2gh5-ph8h

Suggest an improvement
Source
https://github.com/advisories/GHSA-4mjx-2gh5-ph8h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-4mjx-2gh5-ph8h/GHSA-4mjx-2gh5-ph8h.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4mjx-2gh5-ph8h
Aliases
Published
2022-10-10T21:07:47Z
Modified
2023-11-08T04:10:17.897125Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Exposure of sensitive Slack webhook URLs in debug logs and traces
Details

Impact

Debug logs expose sensitive URLs for Slack webhooks that contain private information.

Patches

The problem is fixed in v1.3.2 which redacts sensitive URLs for webhooks.

Workarounds

Disabling/filtering debug logs in case you use Slack webhooks using tracing log level and filters.

References

https://github.com/abdolence/slack-morphism-rust/releases/tag/v1.3.2

For more information

If you have any questions or comments about this advisory: * Open an issue in repo * Read our security policy

Database specific
{
    "nvd_published_at": "2022-10-10T15:15:00Z",
    "github_reviewed_at": "2022-10-10T21:07:47Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-1258"
    ]
}
References

Affected packages

crates.io / slack-morphism

Package

Name
slack-morphism
View open source insights on deps.dev
Purl
pkg:cargo/slack-morphism

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.2