Intel

AIKIDO-2024-10538

EVerest.everest-core is vulnerable to Debug Messages Revealing Unnecessary Information

Debug Messages Revealing Unnecessary Information Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 16, 2024

20

Low Risk

This Affects:

c++EVerest.everest-core
2022-11.0 - 2024.10.0
Fixed in 2024.11.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package expose sensitive tokens by logging them to the console. This can lead to security risks, including unauthorized access or token leakage, especially in environments where console logs are accessible or retained.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

EVerest.everest-core is vulnerable to Debug Messages Revealing Unnecessary Information in versions 2022-11.0 - 2024.10.0.

How to fix this

Upgrade the EVerest.everest-core library to the patch version.