Debug logs expose sensitive URLs for Slack webhooks that contain private information.
The problem is fixed in v1.3.2 which redacts sensitive URLs for webhooks.
Disabling/filtering debug logs in case you use Slack webhooks using tracing log level and filters.
https://github.com/abdolence/slack-morphism-rust/releases/tag/v1.3.2
If you have any questions or comments about this advisory: * Open an issue in repo * Read our security policy
{
"github_reviewed": true,
"nvd_published_at": "2022-10-10T15:15:00Z",
"github_reviewed_at": "2022-10-10T21:07:47Z",
"cwe_ids": [
"CWE-1258"
],
"severity": "HIGH"
}