CVE-2022-39292
Summary
| CVE | CVE-2022-39292 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-10 15:15:00 UTC |
| Updated | 2022-10-11 18:13:00 UTC |
| Description | Slack Morphism is a modern client library for Slack Web/Events API/Socket Mode and Block Kit. Debug logs expose sensitive URLs for Slack webhooks that contain private information. The problem is fixed in version 1.3.2 which redacts sensitive URLs for webhooks. As a workaround, people who use Slack webhooks may disable or filter debug logs. |
Risk And Classification
Problem Types: CWE-1258
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Slack Morphism Project | Slack Morphism | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release v1.3.2 · abdolence/slack-morphism-rust · GitHub | MISC | github.com | |
| cve-website | MISC | www.cve.org | |
| Exposure of sensitive Slack webhook URLs in debug logs and traces · Advisory · abdolence/slack-morphism-rust · GitHub | CONFIRM | github.com | |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.