Intel

AIKIDO-2024-10125

@cap-js-community/odata-v2-adapter is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 13, 2024

20

Low Risk

This Affects:

JS@cap-js-community/odata-v2-adapter
1.10.0 - 1.12.9
Fixed in 1.12.10
Are you affected? Scan for Free

TL;DR

Affected versions of @cap-js-community/odata-v2-adapter may expose authorization headers in debug traces, which could potentially be sent to monitoring tools like Sentry.

Who does this affect?

You are affected if you use a vulnerable version of @cap-js-community/odata-v2-adapter.

Background info

@cap-js-community/odata-v2-adapter is vulnerable to Information Disclosure in versions 1.10.0 - 1.12.9.

How to fix this

Upgrade @cap-js-community/odata-v2-adapter to a patch version.