GHSA-mjv9-vp6w-3rc9
AWS SDK for Rust will log AWS credentials when TRACE-level logging is enabled for request sending
Details
The `aws_sigv4::SigningParams` struct had a derived `Debug` implementation. When debug-formatted, it would include a user's AWS access key, AWS secret key, and security token in plaintext. When TRACE-level logging is enabled for an SDK, `SigningParams` is printed, thereby revealing those credentials to anyone with access to logs.
### Impact All users of the AWS SDK for Rust who enabled TRACE-level logging, either globally (e.g. `RUST_LOG=trace`), or for the `aws-sigv4` crate specifically.
### Patches - Versions >= `0.55.1` - `0.54.2` - `0.53.2` - `0.52.1` - `0.51.1` - `0.50.1` - `0.49.1` - `0.48.1` - `0.47.1` - `0.46.1` - `0.15.1` - `0.14.1` - `0.13.1` - `0.12.1` - `0.11.1` - `0.10.2` - `0.9.1` - `0.8.1` - `0.7.1` - `0.6.1` - `0.5.3` - `0.3.1` - `0.2.1`
### Workarounds Disable TRACE-level logging for AWS Rust SDK crates.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.55.0Fixed in: 0.55.1Upgrade aws-sigv4 to 0.55.1 or newer (ecosystem crates.io).
0.54.1Fixed in: 0.54.2Upgrade aws-sigv4 to 0.54.2 or newer (ecosystem crates.io).
0.53.1Fixed in: 0.53.2Upgrade aws-sigv4 to 0.53.2 or newer (ecosystem crates.io).
0.52.0Fixed in: 0.52.1Upgrade aws-sigv4 to 0.52.1 or newer (ecosystem crates.io).
0.51.0Fixed in: 0.51.1Upgrade aws-sigv4 to 0.51.1 or newer (ecosystem crates.io).
0.49.0Fixed in: 0.49.1Upgrade aws-sigv4 to 0.49.1 or newer (ecosystem crates.io).
0.48.0Fixed in: 0.48.1Upgrade aws-sigv4 to 0.48.1 or newer (ecosystem crates.io).
0.47.0Fixed in: 0.47.1Upgrade aws-sigv4 to 0.47.1 or newer (ecosystem crates.io).
0.46.0Fixed in: 0.46.1Upgrade aws-sigv4 to 0.46.1 or newer (ecosystem crates.io).
0.15.0Fixed in: 0.15.1Upgrade aws-sigv4 to 0.15.1 or newer (ecosystem crates.io).
0.14.0Fixed in: 0.14.1Upgrade aws-sigv4 to 0.14.1 or newer (ecosystem crates.io).
0.13.0Fixed in: 0.13.1Upgrade aws-sigv4 to 0.13.1 or newer (ecosystem crates.io).
0.12.0Fixed in: 0.12.1Upgrade aws-sigv4 to 0.12.1 or newer (ecosystem crates.io).
0.11.0Fixed in: 0.11.1Upgrade aws-sigv4 to 0.11.1 or newer (ecosystem crates.io).
0.10.1Fixed in: 0.10.2Upgrade aws-sigv4 to 0.10.2 or newer (ecosystem crates.io).
0.9.0Fixed in: 0.9.1Upgrade aws-sigv4 to 0.9.1 or newer (ecosystem crates.io).
0.8.0Fixed in: 0.8.1Upgrade aws-sigv4 to 0.8.1 or newer (ecosystem crates.io).
0.7.0Fixed in: 0.7.1Upgrade aws-sigv4 to 0.7.1 or newer (ecosystem crates.io).
0.6.0Fixed in: 0.6.1Upgrade aws-sigv4 to 0.6.1 or newer (ecosystem crates.io).
0.5.2Fixed in: 0.5.3Upgrade aws-sigv4 to 0.5.3 or newer (ecosystem crates.io).
0.4.1Fixed in: 0.4.2Upgrade aws-sigv4 to 0.4.2 or newer (ecosystem crates.io).
0.3.0Fixed in: 0.3.1Upgrade aws-sigv4 to 0.3.1 or newer (ecosystem crates.io).
0.2.0Fixed in: 0.2.1Upgrade aws-sigv4 to 0.2.1 or newer (ecosystem crates.io).