Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS05OWo3LW1oZmgtdzg0cM4AAtgn
Slack Morphism for Rust before 0.41.0 can leak Slack OAuth client information in application debug logs
Impact
Potential/accidental leaking of Slack OAuth client information in application debug logs.
Patches
More strict and secure debug formatting was introduced in v0.41 for OAuth secret types to avoid the possibility of printing sensitive information in application logs.
Workarounds
Don't print/output in logs request and responses for OAuth and client configurations.
For more information
If you have any questions or comments about this advisory:
- Open an issue in the repo
- Email us at [email protected]
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05OWo3LW1oZmgtdzg0cM4AAtgn
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 2 years ago
Updated: 9 months ago
CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Identifiers: GHSA-99j7-mhfh-w84p, CVE-2022-31162
References:
- https://github.com/abdolence/slack-morphism-rust/security/advisories/GHSA-99j7-mhfh-w84p
- https://github.com/abdolence/slack-morphism-rust/releases/tag/v0.41.0
- https://nvd.nist.gov/vuln/detail/CVE-2022-31162
- https://github.com/abdolence/slack-morphism-rust/pull/133
- https://rustsec.org/advisories/RUSTSEC-2022-0086.html
- https://github.com/abdolence/slack-morphism-rust/commit/4923fb7d458ed28c0302244c54cb4df0acee7ee6
- https://github.com/advisories/GHSA-99j7-mhfh-w84p
Blast Radius: 6.8
Affected Packages
cargo:slack-morphism
Dependent packages: 3Dependent repositories: 8
Downloads: 191,983 total
Affected Version Ranges: < 0.41.0
Fixed in: 0.41.0
All affected versions: 0.1.0, 0.1.1, 0.2.0, 0.2.1, 0.2.2, 0.2.3, 0.2.4, 0.2.5, 0.2.6, 0.2.7, 0.2.8, 0.3.0, 0.3.1, 0.4.0, 0.5.0, 0.5.1, 0.5.3, 0.5.5, 0.6.0, 0.6.1, 0.7.0, 0.7.1, 0.7.2, 0.7.3, 0.8.0, 0.8.1, 0.8.2, 0.8.3, 0.8.4, 0.8.5, 0.9.0, 0.10.0, 0.11.0, 0.12.0, 0.14.0, 0.15.0, 0.16.0, 0.17.0, 0.18.0, 0.19.0, 0.20.0, 0.21.0, 0.22.0, 0.23.0, 0.24.0, 0.25.0, 0.26.0, 0.27.0, 0.28.0, 0.29.0, 0.30.0, 0.31.0, 0.32.0, 0.33.0, 0.34.0, 0.35.0, 0.36.0, 0.37.0, 0.38.0, 0.39.0, 0.40.0
All unaffected versions: 0.41.0, 1.0.0, 1.1.0, 1.2.0, 1.2.1, 1.2.2, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.4.0, 1.4.1, 1.4.2, 1.5.0, 1.6.0, 1.6.1, 1.7.0, 1.8.0, 1.9.0, 1.10.0, 1.11.0, 1.12.0, 1.14.0, 1.14.1, 1.14.2, 1.14.3, 1.14.5, 1.15.0, 1.15.1, 1.16.0, 1.16.1, 1.17.0, 2.0.0, 2.1.0