GHSA-4mjx-2gh5-ph8h

    Dashboard / Vulnerabilities / GHSA-4mjx-2gh5-ph8h

    GHSA-4mjx-2gh5-ph8h

    Published: 10 Oct 2022Last Modified: 8 Nov 2023

    Summary: Exposure of sensitive Slack webhook URLs in debug logs and traces

    Details: ### Impact Debug logs expose sensitive URLs for Slack webhooks that contain private information. ### Patches The problem is fixed in v1.3.2 which redacts sensitive URLs for webhooks. ### Workarounds Disabling/filtering debug logs in case you use Slack webhooks using tracing log level and filters. ### References https://github.com/abdolence/slack-morphism-rust/releases/tag/v1.3.2 ### For more information If you have any questions or comments about this advisory: * Open an issue in [repo](https://github.com/abdolence/slack-morphism-rust) * Read our [security policy](https://github.com/abdolence/slack-morphism-rust/blob/master/SECURITY.md)

    Affected packages

    Package

    Name: slack-morphism

    Purl: pkg:cargo/slack-morphism

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.3.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-4mjx-2gh5-ph8h | CVE-DB