VDB
Sign up
MEDIUM5.0

GHSA-p77h-hv6g-fmfp

Sensitive Data Exposure in ibm_db

Quick fix

GHSA-p77h-hv6g-fmfp — ibm_db: upgrade to the fixed version with the command below.

npm install ibm_db@2.6.0

Details

Versions of `ibm_db` prior to 2.6.0 are vulnerable to Sensitive Data Exposure. The package printed database credentials in plaintext in logs while in debug mode.

## Recommendation

Upgrade to version 2.6.0 or later and ensure sensitive information was not logged.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ibm_db
Introduced in: 0Fixed in: 2.6.0
Fixnpm install ibm_db@2.6.0

References