Slack Morphism for Rust before 0.41.0 can leak Slack OAuth client information in application debug logs
High severity
GitHub Reviewed
Published
Jul 16, 2022
in
abdolence/slack-morphism-rust
•
Updated Jul 24, 2023
Description
Published to the GitHub Advisory Database
Jul 20, 2022
Reviewed
Jul 20, 2022
Published by the National Vulnerability Database
Jul 22, 2022
Last updated
Jul 24, 2023
Impact
Potential/accidental leaking of Slack OAuth client information in application debug logs.
Patches
More strict and secure debug formatting was introduced in v0.41 for OAuth secret types to avoid the possibility of printing sensitive information in application logs.
Workarounds
Don't print/output in logs request and responses for OAuth and client configurations.
For more information
If you have any questions or comments about this advisory:
References