Bybit.Net is vulnerable to Generation of Error Message Containing Sensitive Information
20
Low Risk
Affected versions of this package are vulnerable to Information Disclosure via Detailed Error Messages due to improperly returning a generic ServerError containing the full exception object even for HTTP 401 Unauthorized responses. An attacker can exploit this vulnerability by systematically probing endpoints with invalid credentials, causing the application to leak sensitive internal information, framework details, or database queries within the exception message of the 401 response, which significantly aids in crafting more sophisticated attacks.
You are affected if you are using a version that falls within the vulnerable range.
Bybit.Net is vulnerable to Generation of Error Message Containing Sensitive Information in versions 3.8.1 - 5.6.0.
Upgrade the Bybit.Net library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant