RUSTSEC-2022-0087

Source
https://rustsec.org/advisories/RUSTSEC-2022-0087
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2022-0087.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2022-0087
Aliases
Published
2022-10-10T12:00:00Z
Modified
2023-11-08T04:10:17.897125Z
Summary
Slack Webhooks secrets leak in debug logs
Details

Debug log formatting made it possible to leak Webhooks secrets into debug logs.

The patched version has introduced more strict checks to avoid this.

Database specific
{
    "license": "CC0-1.0"
}
References

Affected packages

crates.io / slack-morphism

Package

Name
slack-morphism
View open source insights on deps.dev
Purl
pkg:cargo/slack-morphism

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0
Fixed
1.3.2

Ecosystem specific

{
    "affected_functions": null,
    "affects": {
        "os": [],
        "functions": [],
        "arch": []
    }
}

Database specific

{
    "cvss": null,
    "informational": null,
    "categories": []
}