GHSA-856x-cp3q-47vg
Dashboard / Vulnerabilities / GHSA-856x-cp3q-47vg
Summary: Insecure Default Configuration in airbrake
Details: Affected versions of `airbrake` default to sending environment variables over an unencrypted HTTP connection. In scenarios where an attacker has a privileged network position, it is possible for them to capture and read these environment variables, which may result in leaking sensitive information. ## Recommendation Update to version 0.4.0 or later, or upgrade from the now-deprecated `airbrake` module to its replacement, [`airbrake-js`](https://www.npmjs.com/package/airbrake-js).
References: https://nvd.nist.gov/vuln/detail/CVE-2016-10530, https://github.com/airbrake/node-airbrake/issues/70, https://github.com/advisories/GHSA-856x-cp3q-47vg, https://www.npmjs.com/advisories/96
Affected packages
Package
Name: airbrake
Purl: pkg:npm/airbrake
Affected ranges
Type: SEMVER
Events:
