Intel

AIKIDO-2024-10193

github.com/launchdarkly/ld-relay/v8 is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

50

Medium Risk

This Affects:

gogithub.com/launchdarkly/ld-relay/v8
6.0.0 - 8.8.1
Fixed in 8.8.2

TL;DR

Affected versions of the package may leak server passwords in a URL, which could be recorded in the log files.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/launchdarkly/ld-relay/v8 is vulnerable to Insertion of Sensitive Information into Log File in versions 6.0.0 - 8.8.1.

How to fix this

Upgrade the github.com/launchdarkly/ld-relay/v8 library to the patch version.