V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2022-39292
CVE
High

Slack Morphism is a modern client library for Slack Web/Events API/Socket Mode and Block Kit. Debug logs expose sensitive URLs for Slack we…

CVSS
7.5
High
EPSS
0.01
p46
Published
2022-01-01
Updated
2022-01-01
Description

Slack Morphism is a modern client library for Slack Web/Events API/Socket Mode and Block Kit. Debug logs expose sensitive URLs for Slack webhooks that contain private information. The problem is fixed in version 1.3.2 which redacts sensitive URLs for webhooks. As a workaround, people who use Slack webhooks may disable or filter debug logs.

Tags · CWE
Pre-auth
CWE-1258
CAPEC-37
CAPEC-150
CAPEC-204
CAPEC-545
Affected products
Slack_morphism ≤ 1.3.0
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.007 · p46
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-150 · CWE-1258
└ via CAPEC-37 · CWE-1258
└ via CAPEC-150 · CWE-1258
└ via CAPEC-150 · CWE-1258
└ via CAPEC-150 · CWE-1258
└ via CAPEC-37 · CWE-1258
└ via CAPEC-150 · CWE-1258
└ via CAPEC-545 · CWE-1258
└ via CAPEC-150 · CWE-1258
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
slack_morphism*Tracked
Source databases
CVE
Related vulnerabilities