azure-ai-evaluation is vulnerable to Insertion of Sensitive Information into Log File
25
Low Risk
Affected versions of this package may expose sensitive information in log files. This issue occurs because adversarial or unsafe prompt data is not properly redacted before being stored in Application Insights telemetry. The fix adds redaction to agent safety run logs, preventing sensitive input data from being recorded.
You are affected if you are using a vulnerable version of the package.
azure-ai-evaluation is vulnerable to Insertion of Sensitive Information into Log File in versions 1.0.0 - 1.13.1.
Upgrade azure-ai-evaluation to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant