GHSA-4mjx-2gh5-ph8h

Source
https://github.com/advisories/GHSA-4mjx-2gh5-ph8h
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-4mjx-2gh5-ph8h/GHSA-4mjx-2gh5-ph8h.json
Aliases
Published
2022-10-10T21:07:47Z
Modified
2023-11-08T04:10:17.897125Z
Details

Impact

Debug logs expose sensitive URLs for Slack webhooks that contain private information.

Patches

The problem is fixed in v1.3.2 which redacts sensitive URLs for webhooks.

Workarounds

Disabling/filtering debug logs in case you use Slack webhooks using tracing log level and filters.

References

https://github.com/abdolence/slack-morphism-rust/releases/tag/v1.3.2

For more information

If you have any questions or comments about this advisory: * Open an issue in repo * Read our security policy

References

Affected packages

crates.io / slack-morphism

Package

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.3.2