GHSA-99j7-mhfh-w84p
Slack Morphism for Rust before 0.41.0 can leak Slack OAuth client information in application debug logs
Details
### Impact Potential/accidental leaking of Slack OAuth client information in application debug logs.
### Patches More strict and secure debug formatting was introduced in v0.41 for OAuth secret types to avoid the possibility of printing sensitive information in application logs.
### Workarounds Don't print/output in logs request and responses for OAuth and client configurations.
### For more information If you have any questions or comments about this advisory: * Open an issue in the [repo](https://github.com/abdolence/slack-morphism-rust) * Email us at [me@abdolence.dev](mailto:me@abdolence.dev)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.41.0Upgrade slack-morphism to 0.41.0 or newer (ecosystem crates.io).
References
- https://github.com/abdolence/slack-morphism-rust/security/advisories/GHSA-99j7-mhfh-w84p[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-31162[ADVISORY]
- https://github.com/abdolence/slack-morphism-rust/pull/133[WEB]
- https://github.com/abdolence/slack-morphism-rust/commit/4923fb7d458ed28c0302244c54cb4df0acee7ee6[WEB]
- https://github.com/abdolence/slack-morphism-rust[PACKAGE]
- https://github.com/abdolence/slack-morphism-rust/releases/tag/v0.41.0[WEB]
- https://rustsec.org/advisories/RUSTSEC-2022-0086.html[WEB]