github.com/athenZ/Athenz is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere
7
Low Risk
Affected versions of this package are vulnerable to sensitive information exposure due to improper logging of CSRF tokens and Okta callback URIs, which could allow an attacker to intercept these values from log files or system outputs and use them to potentially predict CSRF token algorithm logic, or manipulate authentication flows by replaying captured tokens or redirecting to malicious callback URIs.
You are affected if you are using a version that falls within the vulnerable range.
github.com/athenZ/Athenz is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 1.12.13 - 1.12.19.
Upgrade the github.com/athenZ/Athenz library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant