GHSA-xr7q-jx4m-x55m
Dashboard / Vulnerabilities / GHSA-xr7q-jx4m-x55m
Summary: Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go
Details: ### Impact This issue represents a potential PII concern. If applications were printing or logging a context containing gRPC metadata, the affected versions will contain all the metadata, which may include private information. ### Patches The issue first appeared in 1.64.0 and is patched in 1.64.1 and 1.65.0 ### Workarounds If using an affected version and upgrading is not possible, ensuring you do not log or print contexts will avoid the problem.
References: https://github.com/grpc/grpc-go/security/advisories/GHSA-xr7q-jx4m-x55m, https://github.com/grpc/grpc-go/commit/ab292411ddc0f3b7a7786754d1fe05264c3021eb, https://github.com/grpc/grpc-go
Affected packages
Package
Name: google.golang.org/grpc
Purl: pkg:golang/google.golang.org/grpc
Affected ranges
Type: SEMVER
Events:
