RUSTSEC-2022-0086

Source
https://rustsec.org/advisories/RUSTSEC-2022-0086
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2022-0086.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2022-0086
Aliases
Published
2022-07-22T12:00:00Z
Modified
2023-11-08T04:09:28.280996Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Slack OAuth Secrets leak in debug logs
Details

Debug log formatting made it possible to leak OAuth secrets into debug logs.

The patched version has introduced more strict checks to avoid this.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / slack-morphism

Package

Name
slack-morphism
View open source insights on deps.dev
Purl
pkg:cargo/slack-morphism

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
0.41.0

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "os": [],
        "functions": [],
        "arch": []
    }
}

Database specific

{
    "cvss": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "informational": null,
    "categories": []
}