@elastic/transport is vulnerable to Debug Messages Revealing Unnecessary Information
10
Low Risk
Affected versions of the @elastic/transport library are vulnerable to the exposure of un-redacted sensitive data through error messages in the log files. Some error messages may include request metadata, such as HTTP headers, where sensitive information like the Authorization header, API tokens, or passwords may be present.
You are affected if you are using a version that falls within the vulnerable range.
@elastic/transport is vulnerable to Debug Messages Revealing Unnecessary Information in versions 8.3.2 - 8.3.4.
Upgrade the @elastic/transport library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant