applicationinsights-agent is vulnerable to Insertion of Sensitive Information into Log File
17
Low Risk
Affected versions of this package may expose user passwords or tokens in logs generated by the self-diagnostics feature of the agent tooling. This occurs due to improper redaction of sensitive information, potentially allowing unauthorized access to credentials if logs are accessed by malicious actors.
You are affected if you are using a version that falls within the vulnerable range.
applicationinsights-agent is vulnerable to Insertion of Sensitive Information into Log File in versions 3.4.5 - 3.6.2.
Upgrade the com.microsoft.azure:applicationinsights-agent library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant