Airbrake keys not being filtered
Critical severity
GitHub Reviewed
Published
Sep 11, 2019
to the GitHub Advisory Database
•
Updated Jul 5, 2023
Description
Published by the National Vulnerability Database
Sep 6, 2019
Reviewed
Sep 11, 2019
Published to the GitHub Advisory Database
Sep 11, 2019
Last updated
Jul 5, 2023
The Airbrake Ruby notifier 4.2.3 for Airbrake mishandles the blacklist_keys configuration option and consequently may disclose passwords to unauthorized actors. This is fixed in 4.2.4 (also, 4.2.2 and earlier are unaffected).
References