elastic-transport is vulnerable to Insertion of Sensitive Information into Log File
20
Low Risk
Affected versions of this package are vulnerable to Information Disclosure due to unsanitized user input in URL and host parameters being directly set as OpenTelemetry span attributes. An attacker can exploit this by crafting malicious URLs containing special characters or payloads that, when processed by the monitoring system's telemetry backend, could lead to log injection, misinterpretation of telemetry data, or potential security incidents in downstream systems that consume these spans without proper sanitization.
You are affected if you are using a version that falls within the vulnerable range.
elastic-transport is vulnerable to Insertion of Sensitive Information into Log File in versions 8.4.0 - 8.4.0 and 8.0.0 - 8.3.5.
Upgrade the elastic-transport library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant