github.com/launchdarkly/ld-relay/v8 is vulnerable to Insertion of Sensitive Information into Log File
30
Low Risk
Affected versions of this package have a vulnerability that leads to Information Disclosure, allowing Redis credentials to be logged without redaction. If an attacker gains access to these application logs, either through a logging console or a log file, they could easily extract the Redis password. With these credentials, the attacker could gain unauthorized access to the Redis database, which might lead to data theft, modification, or deletion.
You are affected if you are using a version that falls within the vulnerable range.
github.com/launchdarkly/ld-relay/v8 is vulnerable to Insertion of Sensitive Information into Log File in versions 8.0.0 - 8.16.0.
Upgrade the github.com/launchdarkly/ld-relay/v8 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant