Skip to content

Exposure of sensitive Slack webhook URLs in debug logs and traces

Low
abdolence published GHSA-4mjx-2gh5-ph8h Oct 9, 2022

Package

cargo slack-morphism (Rust)

Affected versions

<= 1.3.0

Patched versions

1.3.2

Description

Impact

Debug logs expose sensitive URLs for Slack webhooks that contain private information.

Patches

The problem is fixed in v1.3.2 which redacts sensitive URLs for webhooks.

Workarounds

Disabling/filtering debug logs in case you use Slack webhooks using tracing log level and filters.

References

https://github.com/abdolence/slack-morphism-rust/releases/tag/v1.3.2

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2022-39292

Weaknesses