matrix-sdk 0.6.0 logs access tokens
Moderate severity
GitHub Reviewed
Published
Oct 25, 2022
to the GitHub Advisory Database
•
Updated Jan 7, 2023
Description
Published to the GitHub Advisory Database
Oct 25, 2022
Reviewed
Oct 25, 2022
Last updated
Jan 7, 2023
When sending Matrix requests using an affected version of
matrix-sdk
in an application that writes logs usingtracing-subscriber
(in a way that includes fields of tracing spans such astracing_subscriber
s default text output from thefmt
module), these logs will contain the user's access token.References