VDB
Sign up
HIGH7.5

GHSA-mgh5-4h95-qj4p

Information Exposure in Snyk Broker

Quick fix

GHSA-mgh5-4h95-qj4p — snyk-broker: upgrade to the fixed version with the command below.

npm install snyk-broker@4.73.1

Details

All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/snyk-broker
Introduced in: 0Fixed in: 4.73.1
Fixnpm install snyk-broker@4.73.1

References