VDB
Sign up
MEDIUM5.5

GHSA-mjv9-vp6w-3rc9

AWS SDK for Rust will log AWS credentials when TRACE-level logging is enabled for request sending

Details

The `aws_sigv4::SigningParams` struct had a derived `Debug` implementation. When debug-formatted, it would include a user's AWS access key, AWS secret key, and security token in plaintext. When TRACE-level logging is enabled for an SDK, `SigningParams` is printed, thereby revealing those credentials to anyone with access to logs.

### Impact All users of the AWS SDK for Rust who enabled TRACE-level logging, either globally (e.g. `RUST_LOG=trace`), or for the `aws-sigv4` crate specifically.

### Patches - Versions >= `0.55.1` - `0.54.2` - `0.53.2` - `0.52.1` - `0.51.1` - `0.50.1` - `0.49.1` - `0.48.1` - `0.47.1` - `0.46.1` - `0.15.1` - `0.14.1` - `0.13.1` - `0.12.1` - `0.11.1` - `0.10.2` - `0.9.1` - `0.8.1` - `0.7.1` - `0.6.1` - `0.5.3` - `0.3.1` - `0.2.1`

### Workarounds Disable TRACE-level logging for AWS Rust SDK crates.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/aws-sigv4
Introduced in: 0.55.0Fixed in: 0.55.1

Upgrade aws-sigv4 to 0.55.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.54.1Fixed in: 0.54.2

Upgrade aws-sigv4 to 0.54.2 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.53.1Fixed in: 0.53.2

Upgrade aws-sigv4 to 0.53.2 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.52.0Fixed in: 0.52.1

Upgrade aws-sigv4 to 0.52.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.51.0Fixed in: 0.51.1

Upgrade aws-sigv4 to 0.51.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.49.0Fixed in: 0.49.1

Upgrade aws-sigv4 to 0.49.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.48.0Fixed in: 0.48.1

Upgrade aws-sigv4 to 0.48.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.47.0Fixed in: 0.47.1

Upgrade aws-sigv4 to 0.47.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.46.0Fixed in: 0.46.1

Upgrade aws-sigv4 to 0.46.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.15.0Fixed in: 0.15.1

Upgrade aws-sigv4 to 0.15.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.14.0Fixed in: 0.14.1

Upgrade aws-sigv4 to 0.14.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.13.0Fixed in: 0.13.1

Upgrade aws-sigv4 to 0.13.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.12.0Fixed in: 0.12.1

Upgrade aws-sigv4 to 0.12.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.11.0Fixed in: 0.11.1

Upgrade aws-sigv4 to 0.11.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.10.1Fixed in: 0.10.2

Upgrade aws-sigv4 to 0.10.2 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.9.0Fixed in: 0.9.1

Upgrade aws-sigv4 to 0.9.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.8.0Fixed in: 0.8.1

Upgrade aws-sigv4 to 0.8.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.7.0Fixed in: 0.7.1

Upgrade aws-sigv4 to 0.7.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.6.0Fixed in: 0.6.1

Upgrade aws-sigv4 to 0.6.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.5.2Fixed in: 0.5.3

Upgrade aws-sigv4 to 0.5.3 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.4.1Fixed in: 0.4.2

Upgrade aws-sigv4 to 0.4.2 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.3.0Fixed in: 0.3.1

Upgrade aws-sigv4 to 0.3.1 or newer (ecosystem crates.io).

crates.io/aws-sigv4
Introduced in: 0.2.0Fixed in: 0.2.1

Upgrade aws-sigv4 to 0.2.1 or newer (ecosystem crates.io).

References