Intel

AIKIDO-2024-10279

zapier-platform-schema is vulnerable to Exposure of Sensitive Information

Exposure of Sensitive Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Sep 18, 2024

24

Low Risk

This Affects:

jszapier-platform-schema
8.3.0 - 15.14.1
Fixed in 15.14.2
Are you affected? Scan for Free

TL;DR

Affected versions of the package may expose sensitive information. When invoking methods such as authentication.oauth1Config.getAccessToken or authentication.oauth2Config.refreshAccessToken, some logger servers return querystring-formatted data that contains sensitive information, such as secrets, which could be exposed and accessed by unauthorized parties.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

zapier-platform-schema is vulnerable to Exposure of Sensitive Information in versions 8.3.0 - 15.14.1.

How to fix this

Upgrade the zapier-platform-schema library to the patch version.