SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-39292

Debug logs expose sensitive URLs for Slack webhooks that contain private information.

HIGH 7.5EPSS 0.72%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.72%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Slack Morphism is a modern client library for Slack Web/Events API/Socket Mode and Block Kit. Debug logs expose sensitive URLs for Slack webhooks that contain private information. The problem is fixed in version 1.3.2 which redacts sensitive URLs for webhooks. As a workaround, people who use Slack webhooks may disable or filter debug logs.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.72% probability · 52th percentile
CISA KEV
Not listed
Weakness
CWE-1258
Affected
slack morphism project/slack morphism
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.