VulnerabilityModified
CVE-2022-39292
Debug logs expose sensitive URLs for Slack webhooks that contain private information.
HIGH 7.5EPSS 0.72%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.72%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Slack Morphism is a modern client library for Slack Web/Events API/Socket Mode and Block Kit. Debug logs expose sensitive URLs for Slack webhooks that contain private information. The problem is fixed in version 1.3.2 which redacts sensitive URLs for webhooks. As a workaround, people who use Slack webhooks may disable or filter debug logs.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.72% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1258
- Affected
- slack morphism project/slack morphism
- Source
- security-advisories@github.com
References
- https://github.com/abdolence/slack-morphism-rust/releases/tag/v1.3.2Release Notes, Third Party Advisory
- https://github.com/abdolence/slack-morphism-rust/security/advisories/GHSA-4mjx-2gh5-ph8hThird Party Advisory
- https://github.com/abdolence/slack-morphism-rust/releases/tag/v1.3.2Release Notes, Third Party Advisory
- https://github.com/abdolence/slack-morphism-rust/security/advisories/GHSA-4mjx-2gh5-ph8hThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.