Intel

AIKIDO-2024-10153

statsig is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 28, 2024

40

Medium Risk

This Affects:

pythonstatsig
0.1.0 - 0.33.0
Fixed in 0.34.0
Are you affected? Scan for Free

TL;DR

Affected versions of statsig expose sensitive information (such as the API key), which may end up in error logging monitoring systems.

Who does this affect?

You are affected if you use a vulnerable version of statsig.

Background info

statsig is vulnerable to Information Disclosure in versions 0.1.0 - 0.33.0.

How to fix this

Upgrade statsig to the patch version.