Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-fc4h-xcf3-qj5f: matrix-sdk 0.6.0 logs access tokens

When sending Matrix requests using an affected version of matrix-sdk in an application that writes logs using tracing-subscriber (in a way that includes fields of tracing spans such as tracing_subscribers default text output from the fmt module), these logs will contain the user’s access token.

ghsa
#git

matrix-sdk 0.6.0 logs access tokens

Moderate severity GitHub Reviewed Published Oct 25, 2022 • Updated Oct 25, 2022

ghsa: Latest News

GHSA-7p9f-6x8j-gxxp: CRI-O: Maliciously structured checkpoint file can gain arbitrary node access