appsignal is vulnerable to Information Disclosure
18
Low Risk
Affected versions of this package store the entire return value of Oban jobs in the result attribute, which may include sensitive data such as API keys or internal system details. This behavior poses a security risk as the data could be exposed through database leaks, logs, or admin interfaces.
You are affected if you are using a version that falls within the vulnerable range.
appsignal is vulnerable to Information Disclosure in versions 2.5.0 - 2.15.6.
Upgrade the appsignal library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant