GHSA-99j7-mhfh-w84p

Source
https://github.com/advisories/GHSA-99j7-mhfh-w84p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-99j7-mhfh-w84p/GHSA-99j7-mhfh-w84p.json
Aliases
Published
2022-07-20T01:30:21Z
Modified
2023-11-08T04:09:28.280996Z
Details

Impact

Potential/accidental leaking of Slack OAuth client information in application debug logs.

Patches

More strict and secure debug formatting was introduced in v0.41 for OAuth secret types to avoid the possibility of printing sensitive information in application logs.

Workarounds

Don't print/output in logs request and responses for OAuth and client configurations.

For more information

If you have any questions or comments about this advisory: * Open an issue in the repo * Email us at me@abdolence.dev

References

Affected packages

crates.io / slack-morphism

Package

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
0.41.0