botbuilder is vulnerable to Generation of Error Message Containing Sensitive Information
25
Low Risk
Affected versions of this package are vulnerable to Information Disclosure via Error Message due to improper error handling in the handleError function of channelServiceRoutes, which directly sends sensitive error traces (including stack details) in HTTP responses. This allows attackers to deliberately trigger errors and extract internal application logic, file paths, or system details by analyzing the verbose error messages, facilitating further exploits like targeted attacks or reconnaissance.
You are affected if you are using a version that falls within the vulnerable range.
botbuilder is vulnerable to Generation of Error Message Containing Sensitive Information in versions 4.7.0 - 4.23.2.
Upgrade the botbuilder library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant