databricks-sdk is vulnerable to Insertion of Sensitive Information into Log File
20
Low Risk
Affected versions of this package are vulnerable to Insecure Logging of Bearer Tokens, where full bearer tokens are logged in exceptions during API request failures and response parsing errors, exposing sensitive credentials in logs despite the debug_headers setting being false. An attacker with access to these logs, such as through insufficiently protected log storage or transmission, could extract the bearer tokens and use them to impersonate users, execute unauthorized API calls, or access sensitive data, leading to potential data breaches or privilege escalation.
You are affected if you are using a version that falls within the vulnerable range.
databricks-sdk is vulnerable to Insertion of Sensitive Information into Log File in versions 0.32.0 - 0.67.0.
Upgrade the databricks-sdk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant